Overview
Swif's Agentic Security policies control and monitor AI agents, such as Claude Code, Codex CLI, Cursor, and OpenClaw, on managed macOS, Windows, and Linux devices. Use this page to find the right policy, check what it requires, and open its full article.
Before you start
Install the Swif Agentic Security agent first. These policies configure the agent; they don't install it. See Getting Started with Swif's Agentic Security for Enterprise.
Install OpenClaw for the OpenClaw policies. The three OpenClaw policies need the OpenClaw gateway on the device.
Open each AI agent at least once. Some policies, such as Destructive Command Guard, need the agent's local files to exist on the device.
Create policies under Agentic Security. In the Swif Admin Console, go to Agentic Security > Policies and select Create new policy.
Available policies
Monitoring
Policy | What it does | Platforms | Device ownership | Learn more |
Swif Agentic Security Logging Policy | Turns audit logging for supported AI-agent activity on or off. Logged actions appear in the device's Agentic Security view, rated Safe, Risky, or Danger. | macOS, Windows, Linux | Company-owned, BYOD | |
Swif ADR Sensor Policy | Collects activity from AI coding agents' local logs using Uber's open-source ADR Sensor, and can upload it to Swif. Supports Claude Code, Codex CLI, Claude Desktop, Cline, Cursor, and Warp. | macOS, Windows, Linux (Claude Desktop and Warp: macOS and Windows only) | Company-owned, BYOD |
Blocking
Policy | What it does | Platforms | Device ownership | Learn more |
Swif Destructive Command Guard (DCG) Policy | Blocks destructive commands, such as | macOS (Apple silicon and Intel), Windows 11 (x64), Linux (Ubuntu 22.04+, Debian 12, Rocky Linux/RHEL 9) | Not stated |
OpenClaw controls
Policy | What it does | Platforms | Device ownership | Learn more |
Swif OpenClaw Tools Access Policy | Controls which tools OpenClaw agents can use: a base tool profile, allowed and denied tools, rules by provider and sender, sandbox rules, elevated commands, agent-to-agent access, and which sessions an agent can see. | macOS, Windows, Linux | Company-owned, BYOD | |
Swif OpenClaw Tools Runtime Policy | Controls how permitted tools run: command timeouts and background behavior, the | macOS, Windows, Linux | Company-owned, BYOD | |
Swif OpenClaw Tools Experimental Policy | Turns OpenClaw's multi-step planning tool on or off. Off by default. Newer OpenClaw versions changed how this feature is configured, so test it with your OpenClaw version. | macOS, Windows, Linux | Company-owned, BYOD |
How the policies fit together
Monitoring policies record what agents do. Blocking and OpenClaw policies limit what they can do. Use both for complete coverage.
Goal | Use |
See what AI agents did on a device | Logging Policy, ADR Sensor Policy |
Stop agents from deleting files or Git history | Destructive Command Guard Policy |
Limit which tools an OpenClaw agent can use | OpenClaw Tools Access Policy |
Limit how long OpenClaw commands run, or restrict file editing | OpenClaw Tools Runtime Policy |
Turn OpenClaw's planning feature on or off | OpenClaw Tools Experimental Policy |
A few things to keep in mind:
Monitoring doesn't block anything. The Logging and ADR Sensor policies record activity but don't stop a risky action.
Access rules take priority in OpenClaw. The Runtime and Experimental policies can't make a tool available if the Tools Access Policy denies it.
Assign one policy of each type per device. If two policies of the same type conflict, the result can depend on which was applied last.
Removing a policy may not undo its settings. For the OpenClaw policies, deploy the settings you want to keep, confirm them, and only then remove the assignment.
Privacy
The Logging and ADR Sensor policies can collect prompts, responses, commands, file paths, and tool results. Before you turn them on, especially on BYOD devices:
Tell users what's collected.
Limit who in your organization can view the data.
Set retention rules for it.
Each policy's article has more detail.
How to use this list
Find the policy you need in the tables above.
Check the platforms and requirements. Devices that don't meet them don't apply the policy.
Open the article for settings, examples, verification steps, and troubleshooting.
Test on a small pilot group before a wider rollout.