# Memnox > Memnox is the context and control plane for autonomous work. It does not sell protection, it sells the ability to safely raise how much an AI agent is allowed to do without a person watching. The agents already do the work; what Memnox adds is a boundary somebody can read, made of three effects and no others, allow, ask and deny, held at the seams every agent acts through, plus the way back when a run goes wrong. The question it is built to answer is not what an agent did last night, it is what you can safely let it do next. Getting there is four questions in this order: what can this agent do, what is it doing, why was that refused, and can it run unattended. Most agents will never voluntarily call a policy engine, so Memnox stands at the seams they act through instead: an MCP proxy that governs Claude Desktop, Cursor, Cline and OpenClaw at once, tool hooks, a shell wrapper, a git credential helper, an egress proxy, and a browser driver gate. Every seam states what it cannot see. A verdict is allow, ask or deny, it is returned in process, and a refusal names the permitted alternative, which is why a coding agent takes the alternative and finishes the task rather than abandoning it. Discovery, observation, explanation, protection and drift all run locally with no account, no cloud and no network, which is architecture rather than a free tier. `npx memnox` reads what can already act on a machine and what that can reach, ranks it into findings, and closes most of them reversibly. Hermes, OpenClaw and Ruflo are read as harnesses rather than as agents, because each runs other agents: the readout counts the principals behind the row, and the tool filters those products already apply are honoured rather than counted past, so a tool a harness excluded is not reported as reachable through it. What none of them can see is the other harness on the same disk, the credentials underneath, and the shell they share, and a set of individually permitted tools that together read, package and send the same subject outward is named as one path. A day of observation then reports what each agent was granted against what it actually used, and writes the narrower policy as a file a person can read, edit and commit. The runtime is Apache-2.0 and can be self-hosted. Putting those agents under Memnox is one command, `memnox setup`, which finds every agent on the machine, asks what the workspace should call each one, shows what that agent can already reach, and asks whether to onboard it, one at a time, and then wires the machine: the interceptors, a baseline rule set and the daemon that pulls the workspace's rules. It adds a single MCP entry to the agent's own config after backing that file up, in JSON, TOML or YAML, keeping the comments and the indentation; the rewrite is read back before it is written and refused unless every server the file held is still there, and offboarding restores the file byte for byte and revokes the credential. Onboarding changes where an agent asks, never what it may do. The account arrives only when a second person does. What the hosted plans price is what only exists above one machine: a census of every agent from four independent sources including the ones nobody owns, roles and principals, policy proposals published only when somebody other than their author approves them, approvals delivered into the rooms people already work in, containment across a fleet, the team graph and its current state as a policy input, cross agent chain detection, compliance evidence, and the readiness checklist that says whether an agent can safely hold more authority than it has. Plans: Free ($0), Pro ($29/month), Team ($18/person/month, from 5 people). Memnox never does the work. No step writes the code or issues the refund. It hands an objective to an agent the team already runs, with the context, the constraints and a capability attached, and records what happened. Secret values, tool arguments and tool results are fingerprinted or summarised, never stored. There is no estimated loss figure, no risk exposure in currency and no score that silently widens a permission, because a number nobody can derive is a number a security reader stops trusting the rest of the output over. ## Product - [Homepage](https://memnox.com): what can already act on your machine, the five steps from watching an agent to leaving it running, and where the rule it is held to came from. - [How it works](https://memnox.com/how-it-works): the arc from one command to a gate in front of every agent, and the table of where that gate can stand, including what each seam is blind to. - [What one agent already reaches](https://memnox.com/tools): every system an agent on one laptop can reach with Memnox nowhere on the machine, grouped and labelled by how the runtime meets it: an MCP server the proxy wraps, a CLI on PATH with a verb table, or a credential and a socket on the disk. It is a count of the problem, never a count of integrations. - [Governance](https://memnox.com/governance): observe, advise and enforce chosen per environment, decisions kept as operating state, who is entitled to which part of the team's work, and the three parts of an agent's identity: the kind it is, the role it holds, and the person it acts for. - [Pricing](https://memnox.com/pricing): the plans, and what each one changes. - [Security](https://memnox.com/security): what is read, what is never stored, per-workspace isolation, and no training on customer data. - [About](https://memnox.com/about): why Memnox exists and what the company holds to. - [FAQ](https://memnox.com/faq): what an agent may decide, who approves, what is recorded, and what happens to the data it reads. - [Contact sales](https://memnox.com/contact): book a demo, or write to support@memnox.com. ## Documentation - [The whole documentation, in one file](https://docs.memnox.com/llms-full.txt): every page below as plain text in a single fetch. Read this rather than the pages if the question is about how Memnox works. - [Documentation](https://docs.memnox.com): the product and the open runtime. - [What Memnox is](https://docs.memnox.com/what-is-memnox): the plain-language explanation. - [Start here: this machine](https://docs.memnox.com/govern/your-machine): what can already act on this laptop, with no account and no network. - [Quickstart](https://docs.memnox.com/quickstart): one command, and an editor is governed. - [How a decision is made](https://docs.memnox.com/how-it-works): resolve, rules, state, hold, record, in that order, with no model in the path. - [Policies](https://docs.memnox.com/govern/policies): what an agent may do, written as TOML in your own repository. - [Approvals](https://docs.memnox.com/govern/approvals): routing a decision to whoever holds the authority. - [Is this actually working](https://docs.memnox.com/operate/coverage): how much is governed, what was granted and never used, and what stops an agent everywhere at once. - [CLI](https://docs.memnox.com/reference/cli): every `memnox` command and what it prints. - [Runtime seams](https://docs.memnox.com/reference/runtime-api): the local socket, the MCP proxy in full, the interceptors and the JSON. - [Security and privacy](https://docs.memnox.com/administer/security): what is stored, where, and for how long. ## Source - [The open runtime](https://github.com/memnox/memnox): Apache-2.0. ## What Memnox is not A question about this category is usually answered by reaching for the nearest familiar product, and every one of these is a product Memnox deliberately is not. It is not another AI agent, not a coding assistant, not an orchestration framework, not a memory database, not a SIEM, not an MCP firewall, and not merely an AI security product. It sits above the agents a team already runs and below the systems those agents act on. It also never does the work. There is no step that writes the code or issues the refund, and there is nothing in it that hands work out to an agent on a schedule of its own. ## What it is for The thing being sold is the amount of work a team can safely delegate, so the ladder is the product rather than any one screen on it. It runs: I have to watch this agent, then Memnox can see what is happening, then Memnox will stop it if something goes wrong, then I trust it enough to leave it running, then I can give it more responsibility. Every rung is a thing somebody can check rather than a score, and the question the product leads with is what you can safely let an agent do next rather than what it did last night. ## Notes - The runtime is a CLI, a socket at ~/.memnox/memnox.sock speaking line-delimited JSON, and files under ~/.memnox/. There is no HTTP API, no port to call and no SDK. The hosted control plane is driven through its console. - Accounts are provisioned by an administrator or through SCIM. There is no open self-registration endpoint, and sign-in is Google only. - Memnox ships no fictional agent. The first run reads the reader's own machine, so there is no sample workspace, no seeded assistant and no staged attack anywhere in the product.