
Execution-layer controls governing what AI workloads can run, read, and connect to
Canyon Road builds on a straightforward objection to prompt-level defences: guardrails that inspect what an agent was asked to do can be talked around, while the file it opens, the host it connects to, and the command it spawns cannot. The company therefore places its controls at the execution layer, watching system calls, network connections, file changes, and tool invocations from AI processes across both employee endpoints and server infrastructure. Each action is resolved in-line as allow, prompt, block, or redirect, with redirection used to steer a request toward a sanctioned alternative rather than failing it outright and pushing the user to work around the control.
Three components divide the problem. Beacon covers supervised AI on endpoints, where tools such as Claude, Cursor, and ChatGPT act under an employee's own credentials and inherit that person's access by default. AgentSH handles the unsupervised case, applying least-privilege policy at the syscall level to agents running inside CI/CD pipelines, containers, and automation, and is published as an open-source policy-enforced shell for AI harnesses and sandboxes. Watchtower is the control plane: it distributes policy across the fleet, routes approval requests to a human when one is required, provides central visibility, and offers a fleet-wide kill switch. Decisions are retained as an audit trail and exported to SIEM.



