> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getunbound.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Coverage

> Which AI coding agents your policies are enforced on, and what each one supports

**A policy you write is enforced on the agents below.** How far it reaches depends on what each agent exposes to a hook.

Discovery is wider than enforcement. Unbound inventories tool families across macOS, Windows and Linux — see [Discovery](/cli/discovery).

## Where your policies are enforced

<table style={{ width: '100%', tableLayout: 'fixed' }}>
  <colgroup>
    <col style={{ width: '17%' }} />

    <col style={{ width: '12%' }} />

    <col style={{ width: '12%' }} />

    <col style={{ width: '9.2%' }} />

    <col style={{ width: '9.2%' }} />

    <col style={{ width: '9.2%' }} />

    <col style={{ width: '9.2%' }} />

    <col style={{ width: '9.2%' }} />

    <col style={{ width: '6.5%' }} />

    <col style={{ width: '6.5%' }} />
  </colgroup>

  <thead>
    <tr>
      <th rowSpan={2} style={{ verticalAlign: 'top', textAlign: 'left' }}>Agent</th>
      <th rowSpan={2} style={{ verticalAlign: 'top', textAlign: 'center' }}>Prompts</th>
      <th rowSpan={2} style={{ verticalAlign: 'top', textAlign: 'center' }}>Terminal</th>
      <th colSpan={5} style={{ textAlign: 'center', borderBottom: '1px solid var(--gray-400, #9ca3af)', paddingBottom: '0.25rem' }}>Native tools</th>
      <th rowSpan={2} style={{ verticalAlign: 'top', textAlign: 'center' }}>MCP</th>
      <th rowSpan={2} style={{ verticalAlign: 'top', textAlign: 'center' }}>Data</th>
    </tr>

    <tr>
      <th style={{ textAlign: 'center', fontWeight: '500' }}>Read</th>
      <th style={{ textAlign: 'center', fontWeight: '500' }}>Write</th>
      <th style={{ textAlign: 'center', fontWeight: '500' }}>Edit</th>
      <th style={{ textAlign: 'center', fontWeight: '500' }}>Delete</th>
      <th style={{ textAlign: 'center', fontWeight: '500' }}>Search</th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td><strong>Claude Code</strong></td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>
    </tr>

    <tr>
      <td><strong>Claude Cowork</strong></td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>
    </tr>

    <tr>
      <td><strong>Cursor</strong></td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>
    </tr>

    <tr>
      <td><strong>Codex</strong></td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>
      <td style={{ textAlign: 'center' }}>—</td>
      <td style={{ textAlign: 'center' }}>—</td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>
    </tr>

    <tr>
      <td><strong>GitHub Copilot</strong></td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>
      <td style={{ textAlign: 'center' }}>—</td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>
    </tr>

    <tr>
      <td><strong>Augment Code</strong></td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>

      <td style={{ textAlign: 'center' }}>
        <Icon icon="check" color="#A78BFA" />
      </td>

      <td style={{ textAlign: 'center' }}>—</td>
    </tr>
  </tbody>
</table>

<Note>
  **Prompts** means the prompt is captured and shown in activity. **Data** means secrets and personal data — an API key, a credential, personal information. On the agents ticked for it, a prompt carrying one is refused before the turn starts. To control what an agent *does*, use a terminal, native-tool or MCP rule.
</Note>

A blank under **Native tools** means a rule does not reach that action through the agent's own tool. Two reasons:

| Why it is blank                               | Example                                                                                                 |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| The agent has no tool of that kind            | Codex has no separate read, edit or delete tool. It has one patch tool, which Unbound treats as a write |
| The agent reports the action after it happens | Cursor reports an edit once the file has changed, so it is logged rather than matched                   |

**The shell is covered on every agent here.** A delete rule stops Claude Code deleting through its own tool *and* through the shell; on Codex it catches the shell route alone, because Codex has no delete tool.

**The action you choose changes the reach.** On **Block**, **Warn** and **Require Slack Approval**, a file rule — read, write or delete — covers both the agent's own tool and the shell. An **Audit** rule reaches the shell only, so pair it with a live rule on the same family when you need both.

[Tool Policies](/policies/tool-policies) has the families, and when to reach for a Custom pattern instead.

## How MCP rules identify a server

An MCP rule matches on the server being called, and most agents name it in the call.

On **GitHub Copilot** and **Augment Code**, a rule matches a server present in that agent's own configuration on the machine; a server missing from it is recorded rather than matched. On **Claude Cowork**, rules match the servers you add; Cowork's own built-in tools are part of the app rather than servers you configure.

<Note>
  **Listing an agent's MCP servers and matching an MCP call are separate things.** [Discovery](/cli/discovery) reads an agent's configuration to inventory its servers; the MCP column is about the moment a call is made.
</Note>

## What Warn looks like on each agent

**A warning is always recorded, on every agent.** What the developer sees depends on what the agent can show:

| Agent                                                  | What the developer sees                                                                                 |
| ------------------------------------------------------ | ------------------------------------------------------------------------------------------------------- |
| **Claude Code**, **Claude Cowork**, **GitHub Copilot** | A prompt asking them to confirm                                                                         |
| **Augment Code**                                       | A prompt on Augment's own high-risk shell rules; anything else runs and is recorded                     |
| **Codex**                                              | The action is refused, as it would be on Block                                                          |
| **Cursor**                                             | The action runs with no prompt from Unbound; the warning is recorded and passed to the agent as context |

On a headless **Claude Code** run — in CI, or through the Agent SDK — there is nobody to prompt, so the action runs unless your organization sets headless warnings to block.

Use **Block** where an action must not happen, and **Require Slack Approval** where a person should decide. On **Augment Code**, use Block for both — it has no way to hold an action open while someone answers.

## Agents pointed at Unbound as a provider

**Roo Code**, **Cline**, **Kilo Code**, **Gemini CLI** and any OpenAI-compatible client connect differently: you point them at Unbound with an API key instead of installing anything alongside them. Their traffic is recorded and their spend is metered. **Tool policies do not apply to them** — those need one of the agents in the table above.

## Discovered, not yet enforced

Unbound detects these agents. Tool policies do not apply to them yet.

| Agent        | Discovered on            |
| ------------ | ------------------------ |
| **OpenCode** | macOS, Windows and Linux |
| **Zed**      | macOS and Linux          |
| **Pi**       | macOS and Linux          |

### Enforcing on one of these today

**Policies are not tied to a particular agent.** A rule matches on what the call is, not on which agent made it — so an agent that reports its tool calls to Unbound gets real decisions back today through the [hooks API](/integrations/api-tool-policy-hooks). All three expose a way to hook in.

What you take on:

* **You write and maintain the client**, including the part that turns a refusal into that agent's own way of stopping. We publish the contract, not an installer.
* **Terminal and MCP rules work. File-tool rules do not** — those reach an agent's built-in tools only for the agents in the table above. Write against the shell.
* **Warn needs a confirmation step of your own.** Until you build one, use **Block**.
* **Budgets and spend limits do not apply.**

<Note>
  **If a device cannot reach Unbound, work continues by default** — a check that cannot run does not stop the developer. Your organization can require the opposite, so an unreachable check blocks instead. See [Settings](/dashboard/settings).
</Note>

## Related

| Page                                             | For                                     |
| ------------------------------------------------ | --------------------------------------- |
| [Tool Policies](/policies/tool-policies)         | Writing the rules these columns enforce |
| [Discovery](/cli/discovery)                      | Every tool family the inventory finds   |
| [Hooks API](/integrations/api-tool-policy-hooks) | The contract a custom client posts to   |
