npx memnox setup # no install: the first run, with no accountnpm install -g memnox # or install itmemnox --help # the commands typed at a terminalmemnox help --all # every commandmemnox help <command> # one command and its flags
Everything here runs on your machine. There is no account, no key and no network
call anywhere in this page. What the runtime writes, it writes under ~/.memnox/
or into the repository you are standing in, and memnox uninstall takes all of
it back out.
After memnox setup, Memnox lives in your agent session: the agent is told the
boundary, reminded of decisions already taken, and can ask Memnox why something
was stopped, what the session did, or to rewind. See
Memnox in your session. So memnox --help lists only
the eight commands a person types at a terminal, and says that everything else
happens in the session. memnox help --all lists every command, all of them
still wired and supported.
This page starts with those eight, then the rest in the order somebody meets
them: see the machine, put the agents under it, write the rules, run one, read
what happened. The ones used least are named at the end.
At the terminal
These are what memnox --help shows. setup, status, doctor and login
are described in full in their sections below.
$memnoxsetup
Put this machine under Memnox, once, with no account. Described in full under The agents on this machine.
$memnoxstatus
Where this machine stands: what is held, and what happened today. Bare memnox shows the same once setup has run.
$memnoxrewind
Put the working tree back to before an agent touched it: files and nothing else, no commit, no branch, no stash. --list for the milestones with the agent, session and reason of each, --to <id> for one of them, --session <id> for before that session first changed anything, --last for the most recent session. It takes its own milestone first, so a rewind is undoable. The agent can ask for the same thing from the session, with its person's approval. The Recover and decide ahead page has the rest.
$memnoxdoctor
What on this machine is risky, why, and the one change that closes each. --wiring says whether each seam is in the path, and --prove attempts a refusal at every seam. Described in full under What can act here.
$memnoxstop
Turn protection off on this machine, on purpose and on the record. Every seam and hook lets everything through without ruling, and the daemon puts nothing back while the stop holds. --for <duration> brings it back on by itself, such as --for 30m or --for 2h, and --reason <text> says why, in the words your team will read. The mode is left as it was, the stop and who made it are written to the record, memnox status shows it first, and a session that starts while it holds is told protection is stopped. On a connected machine the team sees the stop on the next sync.
$memnoxstart
Turn protection back on, in exactly the mode it was stopped in. Where a timed stop already ran out, it says so rather than recording a start of its own.
$memnoxupdate
Print the installed version and the latest published one, and upgrade only after you say yes, with the command for how this copy was installed, npm or pnpm. From the npx cache, or anywhere the path does not say, it prints the command instead of guessing. After the upgrade the new copy runs the same wiring setup draws, so the hooks and the daemon point at it, and the rules are left alone. Offline, it says so and changes nothing.
$memnoxlogin
Connect this machine to a workspace, so it gets your rules. Described in full under Connecting to a workspace.
Options several commands accept
Option
--json
The structured form instead of the human one. The human wording may change;
the JSON is the contract. Accepted by scan, agents, explain, doctor,
why, timeline, watch, approvals, collisions and trace.
-f, --file <path>
Which policy file to read. Defaults to whichever of
memnox.policies.toml or memnox.policies.yaml exists here.
--no-probe
Do not start MCP servers to ask what they hold. Starting somebody else's
server is the one thing a scan does that runs code, so this turns it off and
tools come from the cache instead.
What can act here
$memnox
What can act on this machine and what it can reach, read off your own disk. The default command on a machine nobody has set up; once memnox setup has run, bare memnox shows memnox status instead and memnox scan is the scan. Credentials lead, and the last two lines are the gap: how much can change something outside this laptop, and how much of that any rule covers.
$memnoxscan--mcp<server>
One MCP server before you trust it: its tools split by what they do, what it can reach, and the risk band with the rules that fired.
$memnoxscan--usage7d
Granted against used. Tools that can change external state and never have are the list protect --from-usage drafts from.
$memnoxscan--share
A card of counts only, safe to paste anywhere. No paths, no names, no values.
$memnoxexplain<subject>
Where one capability came from: a tool, a path, a server, an agent or an authenticated CLI. For a CLI it prints the credential, the projects it is linked to, the verb table and the rule that governs it, and that verb table is the one enforcement reads.
$memnoxdoctor
What is risky, why, and the one change that closes each. --wiring answers a different question: whether Memnox is gating anything at all right now, and it names the rule set in force by content hash. --prove goes further and attempts a refusal at every seam.
$memnoxscan--since<when>
What changed since the last saved scan, which is the same scan compared against the one already kept. --fail-on write-capable exits non-zero in CI when something widened, and --from/--to compares two saved scans.
The agents on this machine
Finding them and putting them under Memnox on this machine needs no account.
Enrolling one into a workspace needs one, because that enrolment is approved by
a person: run memnox login, then memnox setup again. See
Enrolling an agent.
$memnoxsetup
The whole first run in one command, with no account and no network call. It finds the agents, MCP servers, CLIs and credentials here, prints what each agent can already reach, and asks once whether to put them under Memnox, because whether to govern something that can read ~/.aws/credentials is a different decision from something that can only read this checkout. It then wires the machine: the interceptors, a hook before every tool call in Claude Code, Codex, Cursor, Gemini CLI and Windsurf where installed, the MCP servers through the proxy, the memnox-session server in each installed agent so it can ask Memnox from inside a session, a baseline rule set, with the secret denies in ~/.memnox/machine.policies.toml so they apply in every repository, and a daemon the operating system keeps running. It stays in observe and ends by saying nothing left the machine. --yes wires without the question, for a terminal nobody is at; without it and without a terminal, nothing is wired. --enforce starts in enforce, --no-probe starts no MCP server, and --url <base> connects to that control plane too, as memnox login does. After memnox login, running it again names each agent in the workspace and puts it there.
$memnoxstatus
Where this machine stands: protected or not, the mode, the agents, the MCP servers, the rules in force, today's actions, asks and denials, the approvals waiting, what is still on probation and until when, agents dormant for thirty days that still hold reach, and whether a workspace is connected. --json for a script. Bare memnox shows the same once setup has run. The daemon keeps the boundary in between: an agent or MCP server installed later is wired automatically, a removed Memnox hook is put back, and each raises a desktop notice.
$memnoxagentsdiscover
Scan this machine for agents and report what was found: each one by the name you gave it, the product it is, and what it can reach. The default subcommand. It asks what to call each one, and Enter keeps the detected name. Where this machine is connected, the scan goes up on the same pass a sync uses.
$memnoxagentslist
What this machine hosts, from the scan already taken rather than a fresh one, and whether each is onboarded. A discovery starts every MCP server it finds and takes seconds; listing is the thing somebody runs twice in a row.
$memnoxagentsname<agent>[name]
Call an agent whatever you call it. The id stays the identity every ledger row is keyed on; the name is what every screen prints, and every command answers to either one. --clear puts the detected name back.
$memnoxagentsstatus<agent>
One agent, and the file that proved each surface it has. The path says who granted the reach, which is the half somebody can act on.
$memnoxagentsonboard[agent]
Enrol one agent, back its configuration up first, and add a single MCP entry named memnox to it. A person approves the enrolment with a device code. --name says what the workspace should call it rather than being asked. With no agent named, it lists what could be onboarded. Authority is unchanged: what the agent may do is still decided on this machine.
$memnoxagentsoffboard<agent>
Put that configuration back from the backup and revoke the credential. Both halves are reported as what happened rather than as what was attempted, because restoring the file and leaving live reach is the wrong half.
$memnoxagentstrust<agent>
End an agent's probation now, on the record, so only your rules decide what it does. An agent the daemon adopted asks before its writes, outward and destructive actions for seven days otherwise. See [Untrusted repositories and new agents](/govern/untrusted).
$memnoxagentscontrol[agent]
Collect what an operator has said to the agents here, one agent or all of them. Printed before it is acknowledged, and a turn is handed over once. A message is not permission.
Writing rules
$memnoxprotect
Proposes reversible steps and prints the undo before it runs anything. --apply writes them, --revert puts the machine back.
$memnoxprotect--yes
Take the recommended answer for every domain and write a baseline. --interactive walks them instead.
$memnoxprotect--for<cliorserver>
Rules for one thing only. For an authenticated CLI this denies the credential file and leaves the CLI working, which is the distinction that makes any of this adoptable.
$memnoxprotect--interceptors
Install the PATH wrappers, so shell and CLI commands meet the rules too. Only binaries this machine actually has are wrapped, and the ones it does not have are named.
$memnoxprotect--hooks
Install git pre-push and pre-commit hooks in this repository, so a denied push stops even when the wrappers are not on PATH.
$memnoxprotect--os-guard
Write a kernel sandbox profile from your filesystem rules. A denied path then stays unreadable even to a binary that never saw a wrapper. Any pattern the kernel cannot express as a literal path is printed rather than dropped.
$memnoxprotect--from-usage30d
Draft ask rules for what was granted and never used. It drafts ask and never deny: unused for thirty days is not the same as never needed.
$memnoxprotect--observe/--enforce
Record verdicts and deny nothing, or apply them. Observe is where a first run starts.
$memnoxprotect--ask<action...>
Always ask a person before these. --deny <action...> never runs them, and --allow <action...> stops asking about something already approved enough times. Written at once, and on an enrolled machine offered to the team on the next sync as a proposal a second admin decides.
$memnoxprotect--revert-claude-hook
Take the edit hook out of Claude Code, and keep it out: the daemon records the decision and does not put it back. --claude-hook puts it back in.
$memnoxprotect--apply-native
Also write these rules into Claude Code's own permissions, with a backup. --revert-native restores the file byte for byte.
$memnoxconfiglist
Every setting and its value. config get <key> and config set <key> <value> for one.
Running an agent under it
$memnoxrun--<agentcommand>
Start an agent with the interceptor directory first on PATH, the governed shell as SHELL, the egress proxy in its proxy variables, a session id, a working-tree milestone, and the kernel sandbox when a profile exists. Writes outside the repository ask in enforce. Hands back the agent's own exit code. --no-milestone skips the milestone, --no-guard the sandbox, --transcript keeps what it printed, and --task, --paths, --repos, --services, --envs, --expect and --role declare what it was asked to do.
$memnoxrun--untrusted--<agentcommand>
For a repository nobody here vouched for: writes stay in it, credentials and home dotfiles are unreadable, the network reaches only this session's proxy and asks for anything but package registries and the model provider, and every outward or destructive action asks. Held by seatbelt on macOS and by Landlock on Linux, which is new; where no kernel can hold it the run refuses to start. See [Untrusted repositories and new agents](/govern/untrusted).
$memnoxwatch
Report what arrives: new servers, new write tools, credentials that became reachable, agents that updated themselves.
$memnoxuninstall
Remove the interceptors, the hooks and the wrapping, and put every backup back. --purge also deletes ~/.memnox, including the history and your rules.
Calls waiting for a person
$memnoxapprovals
Calls held for somebody to answer. A hold written to disk is what lets a second terminal release something the first is still waiting on.
$memnoxapprove<id>
Release one. First answer wins; a second is told what already happened rather than shown a failure.
$memnoxdeny<id>
Refuse one.
Connecting to a workspace
Optional, and off until you run it. Everything above works with no account and no
network; this is the only part of the runtime that talks to anything, and with no
account file it makes no call at all. See
Connecting to a workspace for exactly what crosses the wire.
$memnoxlogin
Connect this machine to a workspace, so it gets the rules that workspace publishes. The one deliberate step towards the cloud, approved in a browser; run memnox setup afterwards to put each agent in the workspace. --url for a different control plane, --enforce to start enforcing, --no-open to print the URL rather than open a browser.
$memnoxlogout
Forget the credential. Rules already pulled stay in force, because a machine that silently stopped being governed would be the worse failure.
$memnoxwhoami
Which workspace this machine is enrolled in, if any. The answer to whether this one is connected at all, which every other question here depends on.
$memnoxsyncnow
Pull the rules and send what happened, immediately rather than on the daemon's next heartbeat.
What you could let it do next
The ledger read backwards. Not what an agent did, but what a person has already
approved often enough that being asked again is the tool wasting their
attention. No model reads any of this: the counts are the argument, and a single
refusal disqualifies rather than averages away.
$memnoxnext
What you could safely stop being asked about, from what you have already approved. --since 30d for the window.
$memnoxnext--agent<name>
What that agent would do on its own and what would still be asked, rendered by asking the engine action by action rather than by summarising the rules. Under next because it answers the same decision from the other side: bare next reads the ledger backwards, this reads the rules forwards. --role <name> for the boundary of a job rather than of a product, --roles for every job the rules name.
What happened
$memnoxtimeline
What the agents on this machine actually did, in order, grouped by session. --since, --agent, --only allow|ask|deny|blocked, and --export jsonl|json|bundle.
$memnoxwhy[id]
Why the last thing that did not simply proceed was decided that way: the rule, the reason, the alternative and the evidence. Read back from the row, never re-evaluated against today's rules.
$memnoxtimeline--exportbundle--outaudit.json
A signed bundle of a period, stating the range it covers and what was excluded.
$memnoxreplay[session]
One session step by step: every action with its verdict, exit codes, breaker trips and who resumed them, holds still waiting and the milestones kept for it, with the five actions before a failure marked. No session, or --last, means the most recent; --json for a script. See [Recover and decide ahead](/govern/recover#replay).
$memnoxdoctor--prove
Ask every seam to refuse something and report what came back. A different question from --wiring, which reads the configuration: this one attempts the action, and the gap between the two is where this fails worst. A seam that is absent has declined the test rather than failed it, and never fails the command.
Everything else
These are in memnox help --all, run exactly the same way and are supported
exactly the same; they are here rather than up there because a first page of
every command is one nobody finishes. memnox help <command> prints the flags
for any of them.
Command
memnox policy check [file]
Read every rule file this machine would load and say what is in force, what
moved and what will not parse. Exits non-zero on a broken file, so CI can run
it. policy use <file> registers one, policy test '<action>' evaluates a
single action and changes nothing.
memnox check '<intent>'
Decide before the loop starts rather than being interrupted half an hour in.
The same engine and rules, run against the actions an intent resolves to,
with nothing executed. Exits non-zero when something would stop.
memnox freeze <subject> --for 2h
Stop external-state actions for a while. Every freeze carries an expiry, and
--lift ends one early.
memnox budget list
What is set and how much is left. budget set <name> adds one with
--actions, --limit, --window and --unit; budget suggest writes a
starting set; budget remove <name> drops one. Counted from the ledger, so
it survives a restart.
memnox paused
Sessions Memnox is holding, and why. memnox resume <session> --by <who>
lets one carry on, and also lifts the wariness a session is put under after
an instruction-shaped tool result. Who lifted it stays in the record.
memnox lock <path>
Hold a path while you work on it, so a second agent waits rather than writing
over you. --for 30m, --list, --release <id>, --forget.
memnox collisions
Two agents in one file, and two agents building one thing. --days <n> for
the window.
memnox trace <id>
One action end to end: the command, the rule that governed it, the exit code,
the duration and the argument digest. When the session kept a transcript, the
tail of what it printed. An id prefix is enough.
memnox report
What your agents did in a window, and what of it was redone. --since 1d.
memnox claims [session]
What an agent said it did, against what the record says it did. Reported and
never refereed: contradicted is the one that matters.
memnox skills
What your agents run on beyond their config: skills they taught themselves
and personas somebody installed. --accept [name] marks them reviewed.
memnox mcp wrap
Repoint every MCP server at the proxy, keeping a backup. mcp unwrap puts
them back byte for byte, and on a machine setup reached it also stops the
daemon wrapping new ones until mcp wrap is run again. mcp trust <server>
ends a newly wrapped server's seven days of probation.
memnox mcp session on|off
Put the memnox-session server into every installed agent, or take it out
of all of them. It is what lets an agent ask Memnox why, status,
replay and decisions, and ask for a rewind its person approves; no
tool on it can approve, trust, lift, change the mode or edit a rule. Off is
recorded, so the daemon leaves it out; after on, restart the agent. See
Memnox in your session.
memnox env
The environment an agent needs when something else starts it.
--format sh|systemd|docker, because a unit file and an image read no shell
profile. It prints; it edits nobody's unit file.
memnox daemon
Hold the rules in one process, and pull what the workspace publishes.
--install hands it to the machine so it starts at login, --status says
whether anything does, --uninstall stops it. On a machine setup reached it
also keeps the boundary: it hooks an agent installed later, puts back a hook
something removed and puts a new MCP server through the proxy, each with a
desktop notice, and never puts back what a person took out on purpose. It
also notices drift on its own, records every config change in the ledger,
flags dormant agents, and runs the egress proxy on 127.0.0.1:8888. Optional for a verdict: an
interceptor that cannot reach it evaluates in process on the same rules.
Not optional for a workspace, because nothing else pulls a rule set or
carries a held call back to a machine nobody is sitting at.
memnox purge
Drop history past the configured retention. --dry-run says what would go.