For developers
Your agent stays your agent.
Keep personal configuration, native terminal behavior, and the CLI workflow you already use. Blue handles policy before launch and then gets out of the way.
Explore supported harnesses
Open-source governance for coding agents
Give every team one trusted way to use Codex, Claude Code, Kimi Code, and OpenCode, while every developer keeps the native CLI they chose.
Blue sits between organization policy and the coding-agent CLIs developers already know. It adds control without replacing their tools or terminal experience.
For developers
Keep personal configuration, native terminal behavior, and the CLI workflow you already use. Blue handles policy before launch and then gets out of the way.
Explore supported harnessesFor platform teams
Publish policy, manage extensions, control versions, connect identity, and see client health across every supported agent.
Explore administrationAuthenticate, ship trusted tooling, move between agents, and pick up remote sessions without giving up the native CLI.
Set policy once, ship trusted tooling, connect identity and inference, and maintain visibility across every supported coding agent.
Choose which coding agents and versions can run, then reject incompatible installations before launch.
02Ship digest-pinned MCP servers, skills, plugins, hooks, subagents, and helper binaries from one catalog.
03Reconcile organization settings into launch-scoped overlays without replacing developers’ personal configuration.
04Connect CLI device authorization and dashboard access with invitations, OIDC, and SCIM provisioning.
05Connect your organization’s inference gateway and keep provider credentials server-side. LiteLLM is the first supported gateway.
06Opt in to native transcript capture using short-lived uploads to operator-controlled object storage.
Blue manages configuration while each agent talks directly to its provider using the developer’s existing credentials.
Connect your organization-operated gateway and route inference with an opaque per-user pseudotoken. LiteLLM is supported first; provider credentials remain on your server.
Deploy with Docker Compose, Helm, and OpenTofu. Keep state in PostgreSQL and S3-compatible storage, or implement the published governance contract in your own services.
Connect to your organization and keep using the coding-agent CLI you already know, now with governance built in.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/BlocksOrg/governance-harness/releases/latest/download/install.sh | sh