Use case · By risk
Check the evidence behind a device report
For administrators responsible for agent client configuration.
A device appearing in inventory does not tell you that its client permissions or hooks are working. Security shows enrolled devices, their reported client and adapter versions, last receipt and policy state. Capture missing or stale configuration as an owned Work task.
Device reports and bypass
Verify an agent client configuration
- 1
Next action
Check the local client settings against the report
- 2
Context
Client and adapter versions
- 3
Evidence
Last receipt and reported policy state
What to put in the task
- Assign the task to the person responsible for the next action.
- Add evidence links and explain what they show in a comment.
- Update the task when the work changes so the next reader has the current state.
Before you rely on it
Command interception depends on your client's hooks or proxy; see the setup guide for Claude Code, Codex, Cursor and other MCP clients.
- Inventory reports are not independent enforcement checks. The current suite cannot remotely change a client permission mode or complete device setup.
- Work must be enabled for the selected account, and you need permission to read or change the task. Security access and device setup are separate.
Related use cases and clients
By riskMCP servers off the org listThe integration has a documented purpose and an accountable reviewer.By riskDestructive operationsThe cleanup has a named owner and a written scope that a reviewer can check.By clientClaude CodeSetup requirements for Claude Code.
All use cases →