One control panel
for every AI agent.
Most agents now ping you when they finish. Pushary is the layer above that: one policy, phone approvals, and an immutable audit trail across Claude Code, Codex, Cursor, and Hermes.
Control, not just notifications
A ping when an agent finishes is table stakes. The hard part is staying in control of many agents at once. That is the control panel.
One policy across agents
Set per-tool rules once and they apply whether the work runs in Claude Code, Codex, Cursor, or Hermes.
Enforced approvals
On agents with hooks, risky shell commands and edits are blocked until you approve them from your phone.
Immutable audit trail
Every question, approval, and notification is recorded append-only, so you have a real record of what your agents did.
Kill switch
Halt a runaway session from your phone. It denies every gated tool call until you release it.
Fleet view
See your parallel agents in one place and tell at a glance which one is blocked on you.
Phone first
Approve, answer, and stop from your lock screen on any phone, with no native app to install.
What each agent gets
Agents with hooks get enforced approvals, so a denied action does not run. Everything else connects over MCP for notifications and questions.
| Agent | Enforced approvals | Notifications and questions | Setup |
|---|---|---|---|
| Claude Code | One command | ||
| Codex | One command | ||
| Cursor | One command | ||
| Hermes | Plugin | ||
| Gemini CLI, Windsurf, any MCP client | Cooperative | Connect via MCP | |
| No-code and custom | Cooperative | REST API |
Common questions
What is an AI agent control panel?
It is one place to set the rules for your AI agents, approve risky actions, and review what they did. Pushary acts as that control panel across Claude Code, Codex, Cursor, and Hermes.
Which agents does it work with?
Claude Code, Codex, Cursor, and Hermes get enforced approvals through hooks. Windsurf and any MCP client connect for notifications and questions. No-code tools can use the REST API.
Can it enforce approvals or only notify?
Both. With hooks, a risky command is blocked until you approve from your phone. With plain MCP it is cooperative, meaning the agent chooses when to ask.
Is the audit trail tamper-proof?
The trail is append-only. Once an interaction is recorded it cannot be altered or removed, the only allowed change is recording your answer once.
How do I stop a runaway agent?
Use the kill switch from your phone. It denies every gated tool call for that session, including ones you would normally auto-approve, until you release it.
How much does it cost?
Paid agent plans start with a 7-day trial at $9.99 per month. The kill switch, full filterable audit, and export are on Agent Pro and Team.
Is Pushary RBAC for AI agents?
Pushary is approval-based access control for AI agents. You set per-tool policies and gate risky actions behind a human tap, which is the practical equivalent of RBAC plus approvals for agents.
Is this AI agent posture management?
Pushary governs what your agents may do at runtime and keeps an immutable audit trail of every decision, which is the runtime control and evidence part of AI agent posture management.
Does it work with ChatGPT/Codex, Cursor, Claude Code, Gemini, and Windsurf?
Yes. Pushary works across all major agents, including Codex, Cursor, Claude Code, Gemini, and Windsurf, through hooks or MCP.
What is least privilege for AI agents?
Least privilege means giving an agent only the tools it needs and requiring a human approval for anything destructive. Pushary enforces this with per-tool policies and phone approvals.
Put your agents on one control panel.
One policy, one audit trail, one phone. Set up in two minutes.
Set up your agent