Introducing ArmorClaude ๐
Security enforcement for Claude Code and Claude Desktop
so an AI agent can't quietly go off-script inside your environment.
Agentic coding is powerful, but it's a trust problem. You ask Claude to do one thing, and somewhere in the run it reaches for a tool you never authorized. In production, that's how data leaks and unintended actions happen.
ArmorClaude closes that gap:
โ Claude declares its plan first before any tool runs, it registers exactly what it intends to use
โ Off-plan tool calls get blocked automatically, we call it intent drift
โ Set allow/deny policy in plain language, from any prompt
โ Everything logged - full audit trail in the ArmorIQ dashboard
Same enforcement in the Claude Code CLI and the Claude Desktop app. One install, active everywhere.
Setup is a single command. ~2 minutes to your first block.
Docs โ https://t.co/jwDJvHYoc8
How ArmorIQ works:
Agent declares its plan before acting
We sign it into an IntentToken bound to the Okta ID-JAG
Every call checked for auth AND intent, pre-execution
Intended vs actual written to a tamper-evident chain
No second directory. Booth EM6.
Introducing ArmorIQ for Developers
A new home for everything happening with our developer community.
Hackathons. Workshops. Bounties. Events. Community calls. Partnerships. And a lot more on the way.
Follow @ArmorIQforDevs and come build with us.
Weโre just getting started!!!
An agent incident shouldn't require a company wide outage.
@jackclarkSF , this is the enterprise layer we're building at ArmorIQ. We already offer per-agent kill switches: block tool calls for a window, or until you lift the block.
Come break one.
90 seconds at booth EM6: imagine an Accounts Payable agent with a valid Okta token tries a payment outside its committed intent. Stopped before execution.
Valid credential. Named owner. Correct scope. Blocked anyway.
Bring the one you think gets through."
@armoriqAI
11 days to Oktane.
88% of orgs report a suspected or confirmed AI agent incident. Every one of those agents was granted access. Auth didn't fail. Intent did.
One off-the-record dinner. Security and platform leaders only.
https://t.co/sHMjPtAmfC
This is Policy Studio in the ArmorIQ console.
Four tools on a claims-triage agent. Two allowed, two held for a human. Everything unlisted blocked by default.
Form, YAML, and Canvas stay in sync. Plain-language readback before you activate.
your AI agents are making real decisions but most teams still hand-write YAML to govern them.
we built Policy Studio to change that. form fields + live YAML preview, always in sync. writing agent policies should feel like building, not babysitting config files.
A table full of sharp minds, thoughtful conversations, and a lot to take away.
Thank you to everyone who joined ArmorIQ at CrowdStrike Fal.Con 2026.
Until the next one!!
Posted about AIQ Graph yesterday. Here's the bit that's hard to explain in text: you ask your topology a question in plain language and it answers from the live graph of your own estate. Agents, servers, tools, policies, all of it.
Eight kinds of things live in an agentic estate: orgs, agents, MCP servers, tools, policies, OPA bundles, intent plans, and individual calls.
Most teams can name maybe three of them in their own environment.
AIQ Graph draws all nine, and the ten relationship types wiring them together.
8/
Find an ungoverned node and the panel offers Attach policy right there. Coverage gap to covered without switching tools.
That's the loop: see the gap, close it, watch enforcement happen in Live.
Every agent, server, tool and policy you own, and how much of it is actually governed
5/
Now flip to Live.
Per-call nodes appear. Active nodes get glow rings. Edges animate as beams, green for success, red for blocked. A LIVE CALLS panel shows calls per minute and every recent invocation.
4/
Click any node and the panel gives you blast radius: how many nodes it reaches within three hops, and how many of those are already critical or in warning.
Not "is this thing risky." How far the damage goes if it is.