Prerequisites
Before setting up the integration, ensure you have:- Unbound CLI: Installed and logged in — see the CLI guide
- Augment Code: VS Code extension or Auggie CLI
Setup with Unbound CLI
Usage
Basic Usage
After configuration, every tool call Augment makes — shell commands, file reads, file writes, edits, and MCP actions — is checked against your policies before the tool runs. A matching Block policy stops the call and tells the agent why. Audit records it. Setup also writes Augment’s ownask-user rules into ~/.augment/settings.json — open that file after setup to see them. They cover the highest-risk shell commands: rm -rf, piping a download into a shell, sudo, chmod 777, a force push, and reads of /etc/shadow, .aws/credentials, ~/.ssh keys, .netrc and .env. A second rule targets MCP tool calls, but don’t count on a prompt there. Rules you added yourself are kept, and re-running setup doesn’t duplicate ours.
Block and Audit are the actions that land on Augment today. A Warn policy allows the command and records it — the same outcome as Audit — with the shell rules above as the developer-facing stop. Require Slack Approval is not ready here: the first attempt is denied with a message telling the agent to retry, and the retry times out before an approver can answer. Use Block where the command must not run.
Security Benefits
Using Augment Code with Unbound Security AI Gateway provides:- Request Monitoring: All Augment tool calls are logged and monitored
- Analytics: See which files and commands Augment touches across your org
- Compliance: Ensure AI interactions meet your organization’s standards
- Audit Trail: Complete visibility into AI usage patterns
Unbound CLI
Install the CLI to set up and manage tools
Tool Policies
Configure security guardrails for AI tools

