vpsguardian●
Local on your device

YOUR SERVER. YOUR RULES.

Control what agents can do.

Manage MCP access, tools and project boundaries in one place.

Operator panel
▤

No server connected

Enter your connection details on the left

Disconnected

MCP Access

Not loaded

Connect to Guardian 0.30.0+ to load the server-side access policy.

Turn off to pause new MCP calls. Running operations are not cancelled.

A cap can restrict, not elevate, an agent's launch mode. Controlled tokens are not independent human approval.

Allowed tools

—

Uncheck to use an explicit allowlist. get_safety_status stays available for recovery.

The tool catalog will appear after connecting.

Custom roots replace VPS_GUARDIAN_PROJECT_ROOTS. An empty custom list blocks project workspaces. Configuration-file tools have their own fixed directories.

No policy loaded.

Policy is saved on the VPS and shared by upgraded Guardian processes running as this SSH user. Older agents must upgrade and reconnect once. This is an MCP boundary, not isolation from root SSH or server-code access.

Server overview optional · read-only · 30s refresh
CPU 01
—%

Processor usage

RAM 02
—%

Memory usage

Disk 03
—%

Root filesystem

Services

systemd
Uptime

—

Swap

—

Last refresh

—

Monitoring also respects the MCP access policy.