# Memnox documentation > Memnox is the context and control plane for autonomous work. It does not sell protection, it sells the ability to safely raise how much an AI agent may do while nobody is watching. Getting there is four questions in this order: what can this agent do, what is it doing, why was that refused, and can it run unattended. This site documents the open runtime, which stands at the seams agents already act through and decides whether an action proceeds, and the hosted control plane, which holds what the team has settled. The runtime, the MCP proxy, the interceptors and the policy schema are Apache-2.0 and documented here in full. It is a CLI, a socket at ~/.memnox/memnox.sock speaking line-delimited JSON, and files under ~/.memnox/. There is no HTTP API, no port to call and no SDK. The hosted control plane is driven through its console, so a page describing an action there names the screen rather than an HTTP route. A verdict is allow, ask or deny, there are no other effects, and a refusal names the permitted alternative so the agent takes it and the work still finishes. Memnox is not another AI agent, not a coding assistant, not an orchestration framework, not a memory database, not a SIEM, not an MCP firewall, and not merely an AI security product. It sits above the agents a team already runs and below the systems those agents act on, and it never does the work itself. Every page below as one plain-text document, which is one fetch rather than thirty: https://docs.memnox.com/llms-full.txt - Product site: https://memnox.com - Source: https://github.com/memnox/memnox ## Docs ### Start here - [Welcome](https://docs.memnox.com): What Memnox is for, and the two doors into it. - [What Memnox is](https://docs.memnox.com/what-is-memnox): Why nobody leaves an agent running, what Memnox does about it, and where the open half ends. - [Quickstart: govern an agent](https://docs.memnox.com/quickstart): memnox setup: one command, and this machine is under Memnox. No account. - [Memnox in your session](https://docs.memnox.com/govern/in-your-session): What the agent is told when a session starts, what it can ask Memnox, and how a person answers without leaving the conversation. - [Quickstart: your team](https://docs.memnox.com/quickstart/team): memnox login, then memnox setup, then the first systems and the first decision, in a browser. - [From install to a rule in force](https://docs.memnox.com/guides/end-to-end): The whole product in the order you meet it, and you can stop after any part of it. ### What can it do - [What can already act here](https://docs.memnox.com/govern/your-machine): What can act on this laptop and what it can reach, where the machine stands now, and the daemon that keeps it there. - [Enrolling an agent](https://docs.memnox.com/govern/agents): Put one agent under Memnox with its config backed up first, take it back out, and reach one an operator needs to say something to. - [When something runs other agents](https://docs.memnox.com/govern/harnesses): Hermes, OpenClaw and Ruflo are harnesses: what is counted behind each row, and what is left to them. - [What changed under you](https://docs.memnox.com/govern/watch): Drift the daemon notices, an action an agent has never taken before, and two agents in one file. - [The runtime and its seams](https://docs.memnox.com/govern/runtime): The open-source gate: what it is, the three places it can stand, and what each seam cannot see. ### What is it doing - [How a decision is made](https://docs.memnox.com/how-it-works): The one question, the five stages that answer it, and the three effects. - [Activity and audit](https://docs.memnox.com/operate/activity-and-audit): The hash-chained record, how to export it, and where to send it. - [Who caused this](https://docs.memnox.com/operate/lineage): Cross-system causation, and the escalation no single verdict can see. ### What may it do - [Writing policies](https://docs.memnox.com/govern/policies): Plain TOML in your repository, matched deterministically, generated from your own machine. - [Approvals and delegation](https://docs.memnox.com/govern/approvals): Pausing an action until a named human decides, and who that human is. - [Connecting to a workspace](https://docs.memnox.com/govern/workspace): The one part that talks to anything, and exactly what it sends. - [Untrusted repositories and new agents](https://docs.memnox.com/govern/untrusted): Writes kept in the repository, the egress proxy, a sandboxed run for a fresh clone, and probation for what just arrived. - [Recover and decide ahead](https://docs.memnox.com/govern/recover): Rewind the working tree from the session or the terminal, replay a session, and check before the loop starts. - [Coding agent permissions](https://docs.memnox.com/guides/agent-permissions): Claude Code, Codex, Cursor, Gemini CLI and Windsurf permissions, what skipping them skips, and how to stop being asked safely. - [Claude Code hooks](https://docs.memnox.com/guides/claude-code-hooks): The hook events that matter for safety, how a PreToolUse hook allows, asks or denies, and one set of hooks for every agent. - [Claude Code sandbox](https://docs.memnox.com/guides/claude-code-sandbox): What /sandbox isolates, how it compares with a dev container and memnox run --untrusted, and what a wall cannot decide. - [MCP proxy](https://docs.memnox.com/guides/mcp-proxy): Transport bridge, gateway or governing proxy, and how the Memnox MCP proxy decides every tool call on your machine. - [From watching it to letting it run](https://docs.memnox.com/guides/observe-to-enforce): Supervising less, one step at a time, without wedging anybody's editor. ### What was it meant to do - [The team graph](https://docs.memnox.com/concepts/team-graph): People, systems and projects, and the evidence behind every claim. - [Decisions and memory](https://docs.memnox.com/concepts/decisions): How a conversation becomes a rule an agent can be held to, and who approved it. - [Need to know](https://docs.memnox.com/concepts/need-to-know): Who is told what, and why an agent never out-reads the person it works for. - [Connected systems](https://docs.memnox.com/integrations): Where the third truth comes from, and why there is no per-tool code here. ### Letting it run, and with a team - [The console](https://docs.memnox.com/operate/console): One tree in five groups, and why each page in it is a page. - [Is this actually working](https://docs.memnox.com/operate/coverage): How much is governed, whether anything is intercepting, and what was granted and never used. - [MCP servers across the team](https://docs.memnox.com/operate/mcp-servers): Every MCP server the team's machines configure, the shadow ones first, and blocking one for everybody. - [Who acts here](https://docs.memnox.com/administer/roles): The people and the agents, in one place: roles and accounts, then identity, authority and how to stop one. - [Security and privacy](https://docs.memnox.com/administer/security): What is stored, what never is, and where the model boundaries sit. ### Open source - [Contributing](https://docs.memnox.com/contribute): How the runtime repo is laid out, and how to get a change merged. ## Reference ### Reference - [Overview](https://docs.memnox.com/reference): Every surface Memnox exposes, in one index. - [CLI](https://docs.memnox.com/reference/cli): The eight commands typed at a terminal, then every other `memnox` command. - [Runtime seams](https://docs.memnox.com/reference/runtime-api): The local socket, the MCP proxy, the interceptors and the JSON. ### Formats and config - [Policy file](https://docs.memnox.com/reference/policy-schema): Every field a rule can carry. - [Configuration](https://docs.memnox.com/reference/configuration): Files, settings and environment variables.