Stop the commands you name before they run
Every command your agents send is checked against your policies. The ones you don’t allow are blocked.
Covers
What it covers
Eight starter policies
Production, branches, secrets and five more, from day one.
Try a rule on the last 30 days
See what a draft would block before you publish it.
It reads what the agent reads
Files, web pages and tool results are scanned too.
Bypass is reported
A session that skips the client’s own permissions shows up.
Claude Code, Codex and Cursor
Each client is covered on every paired Mac.
One install for the team
The org installs the hook on every Mac. Nobody sets it up by hand.
Every decision on the record
Each check lands in Events with the agent, the project and the reason.
Ask for an exception in one click
A blocked agent or person asks. You allow it once, for a while, or decline.
How it decides
Only commands that pass through the Specify hook are checked. These pages say how.
- Access and decisions
- Policy boundaries
- Event records
- Set up Claude Code
- Set up Codex
- Set up Cursor
- Set up the MCP proxy
The adapter may use your local GitHub sign-in to read a repository's default branch, and only for that, sending it to GitHub and never to Specify.