every MCP server declared on this machine: where it is configured, whether its calls pass through Prismor, what it has been doing in the last 7 days, and how each tool is handled
Loading MCP servers…
Extensions
Skills, plugins, MCP servers and third-party hooks: anything installed on this machine that can put instructions or code into an agent. Prismor records each one when it first appears and again when its files change, so you can read it once and know it has not moved since.
Loading extensions…
What changed, when ?
No extension events yet.
Docs
The Prismor docs shipped with this install — browse or search without leaving the dashboard.
Pages
Loading docs…
Pick a page to read it here.
Needs attention
Checking…
Prismor screens every tool call your agents make on this machine and decides it against the policy in force before it runs. Words used here: a call is one tool use; the decision is allowed, warned or blocked; a rule fired is one policy rule that matched, block or not.
–
allowed
Allowed-
Blocked-
Rules fired ?-
Agent activity · last 7 days
Calls screened ?
-
Blocked ?
-
Sessions ?
-
– agents registered on this machine
Rules fired ?
-
- critical · - high · - medium · - low
How Prismor decides one tool call show
01
Request
The agent asks. Nothing has run yet.
–
02
Identity
Which agent, which session, which workspace.
–
03
Policy
The rules in force are evaluated locally, as code.
–
04
Decision
Allowed, warned, or blocked, before anything runs.
–
05
Evidence
Recorded to the local ledger, synced when enrolled.
–
Recent Sessions
Clean runs appear here too, even when there are no findings.
Session
Agent
Status
Last Active
Threats by Category
Block Rate — 30 days
Blocked Commands by Agent
Tool Call Breakdown
Top MCP Servers & Skills
Supply Chain
last 7 days
Allowed
-
Warned
-
Blocked
-
Total Checked
-
Ecosystems
Recent Blocks & Warnings
Package
Eco
Score
Advisory
Suggested
When
Install Activity by Session
Session
Eco
Install Command
Allowed
Warned
Blocked
When
Findings & Events
Top Sessions by Blocks
Top Threat Patterns
Pattern
Category
Count
Last Seen
Severity
Findings Drilldown
Finding
Agent
Category
Severity
When
Event Feed
Agent Control
per-agent kill switch, enforcement mode & IAM profile — live agents pick changes up within 30 s
Manage every agent from one place
Claude Code, Codex, Cursor, and other agents auto-register the first time they run in a
Prismor-enabled workspace. Blocked denies every tool call from that agent
(kill switch) · Observe logs threats without blocking ·
Enforce blocks them in real time. Saved to .prismor/agents.yaml.
Agent
Status
Mode
Calls
Blocked
Last Seen
Enabled
Loading agents…
Live Sessions
pause Prismor, clear scope, or unblock a stuck agent — per-agent kill switch lives in the Agents tab
Loading sessions…
All Sessions
full session log — click session row above for controls
Select a node in the flow to inspect the tool call, its verdict, and the policy that decided it.
Policy Control
human-only — changes take effect within 30 s on running agents
Which policy governsLoading…Show the four layers
YAML files
blocks stops the callreports records it, the call proceeds Pinned safety floor, cannot be turned offA toggle decides whether a rule runs at all. Whether it blocks or reports comes from the policy's enforce selection. Saved to the project policy file; agents pick it up within 30 s.
—
Loading…
Where agents may connect
Off by default. Turn it on in observe first and read
prismor egress report — it lists every destination your recorded sessions
actually contacted, so you can see what enforcing would have broken before it breaks it.
Saved to .prismor/policy.yaml under settings.egress.
Loading…
Screening
Enforcement mode
Unlisted destinations
Global policy — not applied by the runtime yet
This file is read and written here, but the policy engine merges only the built-in
defaults, the project file, and any org policy — so edits below do not currently change
what agents are allowed to do. Use the Project tab, or
prismor setup, to change enforcement.
Path: ~/.prismor/policy.yaml
Loading…
Enforcement mode
observe = log only · enforce = block
Project policy
Overrides global settings for this project only. Stored in
.prismor/policy.yaml alongside your code.
Merge precedence: enterprise > project > global.
Loading…
Enforcement mode
observe = log only · enforce = block
Not enrolled
Enroll this device in a Prismor org to receive centrally-managed policies.
Run: prismor enroll <token>
Read-only — managed by your org admin in the Prismor web dashboard.
Effective policy
What actually runs on this machine right now — global + project + enterprise merged together.
Enterprise settings take precedence; core protections can never be disabled.
Read-only — edit Global or Project to change this.
Fleet
org-wide visibility across every enrolled device
Fleet view is a Prismor Enterprise feature
This local dashboard shows agents and sessions on this machine. Fleet view gives
your security team the same picture across every developer laptop and CI runner in the org —
live sessions, findings, per-device policy status, and a remote kill switch — streamed as
redacted telemetry to a dashboard you host.
Device
User
Agents
Mode
Findings (7d)
Last Seen
mbp-eng-042
priya@acme.dev
claude-code, codex
enforce
3
2m ago
mbp-eng-017
sam@acme.dev
claude-code
enforce
0
11m ago
ci-runner-08
—
codex
enforce
1
just now
mbp-eng-063
jo@acme.dev
cursor
observe
7
1h ago
mbp-eng-029
lee@acme.dev
claude-code, cursor
enforce
0
3h ago
Illustrative preview — live fleet data is part of Prismor Enterprise
Rolling Prismor out to a team?This local dashboard stays free and open source. Enterprise adds fleet visibility, signed remote policy, org kill switch, and audit history.
The local dashboard is free and open source, forever — Enterprise adds the cloud control plane on top, nothing here is taken away.
Prefer chat? Join our Discord.