Securing Claude Code: Ceros Offers Visibility & Control for Security Teams.
Mar 19, 2026 // 14:03 - Norina Velotta


Security departments have been developing identity and access management for users and service accounts for a long time. However, a new kind of user has emerged in most companies, operating without those controls.

Anthropic’s AI coding assistant, Claude Code, is now widely used in engineering departments. It accesses files, runs commands, uses external APIs, and connects to third-party services called MCP servers. It does this independently, with the same permissions as the developer who started it, on the developer’s computer, before network security can detect it. It leaves no record that current security systems can track.

This guide explains Ceros, an AI security layer by Beyond Identity that works directly on the developer’s device with Claude Code. It provides real-time monitoring, enforces policies, and creates a secure record of every action the assistant takes.

Before exploring the product, it’s important to understand why current tools can’t solve this issue.

Most company security tools monitor the network or API. These tools only see activity after it leaves the computer. By the time a security system detects or flags something, Claude Code has already acted: the file has been accessed, the command has been run, and the data has been transferred.

Claude Code’s behavior complicates the problem. It uses existing tools and permissions on the developer’s computer. It communicates through what appears to be normal network traffic. It performs complex actions without direct programming. And it has all the permissions of the user who launched it, including access to credentials, systems, and data on the developer’s computer.

The result is a blind spot that network tools can’t fix: everything Claude Code does on the local machine, before any request leaves the device. Ceros addresses this.

Ceros is designed to not interrupt developers. Setup requires two commands:

The first command installs the CLI. The second starts Claude Code through Ceros. A browser window will appear, asking for an email address and sending a verification code. After entering the code, Claude Code will start and work as it did before. From the developer’s point of view, nothing changes.

For company-wide use, administrators can set up Ceros to automatically ask developers to enroll when they start Claude Code. Security is unnoticeable, making it more likely to be adopted.

Once enrolled, before Claude Code starts, Ceros gathers information about the device, including OS, kernel version, disk encryption status, Secure Boot state, and security software status, in less than 250 milliseconds. It records how Claude Code was started. And it connects the session to a confirmed user through Beyond Identity’s platform, secured with a cryptographic key.

After enrolling a device and using Claude Code as normal for a few days, the Ceros admin console shows a record of Claude Code’s activities across the organization.

The Conversations view lists every session between a developer and Claude Code on every enrolled device, sorted by user, device, and time. Clicking on a session shows the full interaction between the developer and the assistant. It also displays tool calls.

When a developer asks Claude Code “what files are in my directory?”, the AI doesn’t know the answer. It tells the assistant to run a tool on the computer, such as bash ls -la. This command runs on the developer’s device with their permissions. A simple question leads to activity on the machine.

The Conversations view shows every tool used in each session. For most security teams, this is new information.

The Tools view has two sections. The Definitions section lists every tool available to Claude Code, including Bash, ReadFile, WriteFile, Edit, and SearchWeb, and every MCP server that developers have connected. Each tool includes instructions for the AI on what it does and how to use it.

The Calls section displays what was actually run, including the arguments and results. Security teams can examine each tool call and see the exact command, arguments, and output.

The MCP Server view often reveals significant findings. MCP servers connect Claude Code to external services, like databases, Slack, email, internal APIs, and infrastructure. Developers add them without considering security. Each one is a potential security risk that hasn’t been reviewed.

The Ceros dashboard shows every MCP server connected to Claude Code, when it was first used, which devices it’s on, and whether it’s been approved. For many companies, the difference between what security teams thought was connected and what is actually connected is large.

Visibility reveals risk, but doesn’t prevent it. The Policies section is where Ceros enforces security and ensures compliance.

Policies in Ceros are checked before an action occurs. This is important for compliance: the action is controlled at the moment it happens.

MCP server allowlisting is the first policy most companies create. Administrators create a list of approved MCP servers and block everything else by default. Any Claude Code connecting to a non-approved MCP server is blocked, and the attempt is recorded.

Tool-level policies let administrators control which tools Claude Code can use and when. A policy can block the Bash tool for teams that don’t need shell access. It can allow file reads in the project directory but block reads in sensitive folders like ~/.ssh/ or /etc/. The policy engine checks both the tool and the arguments, making the policy effective.

Device posture requirements check the device’s security before Claude Code starts. A policy can require disk encryption and active security software. Ceros continuously monitors the device’s security during the session. If security software is disabled, Ceros will respond based on the policy.

The Activity Log is important for compliance teams. Each entry is a record and a capture of the environment at the time Claude Code was used.

A log entry contains the device’s security status, how Claude Code was started, signatures of every program involved, the user identity, and every action Claude Code took.

Auditors require proof that logs are unchangeable. Standard log files that can be edited don’t meet this requirement. Ceros signs each entry with a hardware-bound cryptographic key before it leaves the device. The log cannot be altered.

For frameworks like SOC 2’s CC8.1, FedRAMP’s AU-9, HIPAA’s audit control requirements, and PCI-DSS v4.0’s Requirement 10, this is the proof that satisfies the requirement. When an auditor asks for evidence of monitoring and access controls on AI assistants, the answer is a signed export from the Ceros dashboard, with user information on every entry.

For organizations that want to standardize the tools available to Claude Code, Ceros offers managed MCP deployment from the admin console.

Administrators can push approved MCP servers to every developer’s Claude Code from one place, without developer configuration. The MCP server appears in the developer’s agent automatically on the next launch.

Combined with MCP server allowlisting, this creates a complete control system: administrators define what is required, allowed, and blocked. Developers work within that framework smoothly.

Coming soon is The Dashboard, a single view of AI risk across your whole organization. Where the session-level views show what one developer’s assistant did, the Dashboard shows what’s happening across the company: how many devices are provisioned, enrolled, and actively running Claude Code, with automatic warnings when agents are running outside of Ceros. Sign up to be notified when The Dashboard is available.

The security vulnerability that Claude Code creates is not on the network. It’s on the developer’s computer, where the assistant works before any security tool can detect it. Ceros fixes this by working where the assistant works, capturing everything before it runs, and providing secure evidence for security and compliance teams.

For security teams whose organizations have deployed Claude Code, visibility is the first step. You can’t control what you can’t see, and until now, no tool could show what Claude Code was doing.

Ceros is available now, and it’s free to start. Security teams can enroll a device and see their Claude Code activity for the first time at beyondidentity.ai.

Ceros is by Beyond Identity, which follows SOC 2 / FedRAMP standards and can be deployed as cloud SaaS, self-hosted, or completely isolated on-premises.

#ceros  #claude  #code  #control  #for  #news  #offers  #securing  #security  #teams  #visibility   —   News