Cloud agents
Some agents run where you cannot install the runtime: a support bot on a server, a fix agent in CI, an on call bot with production credentials. Memnox Cloud puts them under the same rules as your laptop, and their questions reach the same people.
| Agent | Runs freely | Waits for a person |
|---|---|---|
| Support bot | reads, replies, order lookups | issuing a refund |
| Dependency bot in CI | gh pr create | gh pr merge, a force push |
| On call bot | kubectl get, logs | kubectl delete, terraform apply |
1. Make a credential
In the console, open Agents and use Connect a cloud agent. Give the agent
a name, such as support-bot, and copy the three values. The token is shown
once.
MEMNOX_TOKEN=<shown once>
MEMNOX_WORKSPACE=<your workspace id>
MEMNOX_URL=https://api.memnox.com2. Pick one way in
The guard library, for code you write
Use this when your agent runs on the Claude Agent SDK, the OpenAI Agents SDK or your own code.
npm i @memnox/guardClaude Agent SDK:
import { query } from "@anthropic-ai/claude-agent-sdk";
import { createGuard, wrapClaudeAgentQuery } from "@memnox/guard";
const guard = createGuard({ agent: "support-bot" });
const governed = wrapClaudeAgentQuery(query, guard);
for await (const message of governed({ prompt: "refund order 4417" })) {
// the agent runs as usual
}
await guard.close(); // send what is left of the recordOpenAI Agents SDK:
import { guardAgentsTools } from "@memnox/guard";
const tools = guardAgentsTools([issueRefund, lookUpOrder], guard, {
session: (run) => run.context.ticketId,
});Any other code:
const decision = await guard.authorize("issue_refund", { order: "4417" }, { sessionId });
if (!decision.allowed) return `Not done: ${decision.reason}`;The MCP gateway, for agents that only speak MCP
No library. First add the real server under Servers behind the gateway on
the same page: a name such as stripe, its address, and its credential. Then
point the agent's MCP client at the gateway instead:
{
"mcpServers": {
"stripe": {
"type": "http",
"url": "https://api.memnox.com/v1/workspaces/<workspace>/gateway/stripe",
"headers": {
"Authorization": "Bearer <MEMNOX_TOKEN>",
"x-memnox-agent": "support-bot"
}
}
}
}Every tool call is checked before it reaches the server. A tool with no rule
that sounds destructive, like delete or refund, is asked about rather than
trusted.
3. Write the rule
The same TOML your laptop uses. Rules your team publishes reach cloud agents on their next fetch.
[[policies]]
name = "refunds-ask-lead"
[policies.match]
actions = [ "mcp.stripe.create_refund" ]
[policies.decision]
effect = "ask"
approvers = [ "support-lead" ]What happens on each call
- Allow and deny are decided inside the agent's process, in microseconds, with no network. They keep working if the cloud is down.
- Ask reaches the agent's owner and the rule's approvers on their iPhone, Mac, Slack or the console. The agent waits, two minutes by default, then stops if nobody answers.
- A loop is paused. Five identical failures pause the session until a person presses Resume in the console or on their phone. The agent cannot resume itself.
- Arguments stay in the agent. Only a fingerprint is sent, and only a yes the cloud signed for these exact arguments is believed.
To refuse a yes that only a chat button gave, require a device:
const guard = createGuard({ agent: "support-bot", requireDeviceProof: true });See what they are doing
Agents in the console lists every cloud agent: how many calls were allowed, asked and refused, its last decisions, what it is waiting on, and any paused session. The iPhone app shows the same page. If your plan does not include cloud agents, the console says so when you make the credential.