The control that matters most is the cheapest: scan what leaves the machine. AccuroAI evaluates assistant context on-device — sixty-plus secret types, protected source paths, custom patterns for your internal identifiers — and redacts before transmission at sub-38ms. Developers keep their flow; the raw values stay home. The failure mode of an engineer’s busy afternoon becomes a masked token, not a rotated-credentials incident.
Claude Code and its peers act — they run commands, edit files, call MCP tools. Action-level policy gives each agent an allowlist, argument inspection, and human sign-off on destructive classes. The Black Hat 2026 case studies cut both ways: real credential-exfiltration research against every major coding agent, and a defender (Roblox) showing that layered containment works.
IDE assistants, CLI agents, and the MCP servers they call are endpoint phenomena — invisible to network security. Device-level inventory shows which assistants run where, with which access, attributed per developer, so policy lands on reality instead of the sanctioned-tools list.
Inspection runs at sub-38ms p99 — imperceptible next to model latency. And the default action is redact-and-continue, so work proceeds; developers typically notice the control only when it catches something they are glad it caught.
Yes — that is the point. Autocomplete-era controls watched suggestions; agentic assistants need action-level policy on what they run, edit, and call. Both layers are covered.
Treat repo files as untrusted input to your build agents: pinned assistant versions, no auto-trusted workspaces, scoped service credentials, and the same context scanning. The 2026 CVE record is the argument.
Yes — policies scope by IdP group. Platform teams commonly run stricter source-path rules; experimentation teams looser prose rules. One engine, per-team dials.