Overview
The Windows Agentic Security Policy installs Swif's Agentic Security agent on managed Windows devices and enrolls them in Agentic Security. Use it to deploy the agent to many devices at once, instead of downloading and running the installer on each one.
Important: This policy only installs the agent. It doesn't monitor or block anything by itself. After the agent is installed, assign Agentic Security policies to choose what it does, such as the Logging Policy to record AI agent activity. Without them, the agent doesn't capture AI agent activity.
Supported platforms and requirements
Item | Details |
Platform | Windows |
Minimum OS | Windows 10 or later |
Device ownership | Company-owned and BYOD Windows devices |
Other requirements | The device must be enrolled in Swif and online |
Settings reference
Setting | What it does | Default |
Enable Agentic Security | On: downloads the Agentic Security agent and enrolls the device in Agentic Security. Off: the policy doesn't install the agent. | Off |
Enable Agentic Security is required, and it's off by default. Turn it on to install the agent.
How it works
You turn on the policy and add devices from the Agentic Security page. Swif sends the policy to those devices.
Swif downloads the Agentic Security agent to each device and installs it.
The agent enrolls the device in Agentic Security for your Swif organization.
The device appears in Agentic Security, ready for Agentic Security policies.
Users don't need to sign up or create a separate account. Devices enroll in your existing Swif workspace.
Before you start
Make sure the Windows devices are enrolled in Swif and online.
Plan which Agentic Security policies to assign after the agent is installed. See the Agentic Security Policy collection.
For BYOD devices, tell users what Agentic Security collects. Monitoring policies can record prompts, responses, commands, and file paths from AI agents.
Set up the policy
You set up this policy from the Agentic Security page, in the Agentic Security Deployment Policies window. There it's listed as Windows Agent Security Policy (Windows 10+), with its status:
Status | Meaning | Button |
Not Configured | The policy hasn't been set up yet. | Configure Policy |
Configured | The policy is set up. Add more devices to it at any time. | Add Devices |
Configure the policy
In Swif, go to Agentic Security.
Click Configure Policies to open Agentic Security Deployment Policies.
Find Windows Agent Security Policy and click Configure Policy.
Turn on Enable Agentic Security.
Save the policy.
Add the Windows devices that should get the agent. Start with a few devices to confirm the agent installs before a wider rollout.
Add devices to the policy
Once the policy shows Configured:
Go to Agentic Security and click Configure Policies.
Find Windows Agent Security Policy and click Add Devices.
Select the Windows devices to add, then save.
Find devices missing the agent
At the bottom of Agentic Security Deployment Policies, Swif shows how many devices are missing the Agentic Security agent. Click Review Devices to see which ones. Then add them to the policy.
Swif also shows a Monitoring Gap Detected banner on the Agentic Security page when it finds devices running AI tools, such as OpenClaw, that the agent isn't monitoring.
Install on a single device
To install the agent on one device by hand instead, click Install Agentic Security at the top of the Agentic Security page and download the installer.
After the agent is installed
In Swif, go to Agentic Security > Policies and assign the policies you need, for example:
Goal | Policy |
Record AI agent activity | |
Collect activity from AI coding agents' local logs | |
Block destructive commands such as |
Example configuration
Developer laptops running Windows 11 with Claude Code, Codex CLI, or Cursor
Step | Policy | Setting |
1 | Windows Agentic Security Policy | Enable Agentic Security: On |
2 | Swif Agentic Security Logging Policy | Logging on |
3 | Swif Destructive Command Guard (DCG) Policy | On |
Swif installs the agent first, then the Agentic Security policies record agent activity and block destructive commands.
Verify the policy
In Swif, open the device and confirm that the policy shows as applied.
Go to Agentic Security and confirm that the device appears in the device list with a recent Last Heartbeat.
Click Configure Policies and check that the number of devices missing the agent has gone down.
After you assign a Logging Policy, open the device's Agentic Security tab and confirm that AI agent activity appears.
Troubleshooting
The agent doesn't install
Check that Enable Agentic Security is on and that the device was added to the policy.
Check that the device is enrolled in Swif and online.
Check the device's Commands tab for errors.
The device doesn't appear in Agentic Security
The agent may still be installing or enrolling. Wait for the device to check in with Swif, then refresh the Agentic Security device list.
The device appears, but no AI agent activity shows
This policy only installs the agent. Assign the Swif Agentic Security Logging Policy to record activity.
