The endpoint agent

Scout

Scout is the endpoint agent that captures judgment-level signal at the device. It discovers and observes AI agent activity across your environment, regardless of which platform or framework those agents run on, and gives the Certiv Policy Engine the context it needs to act before an agent does.

TerminalShellEditViewWindowHelp
Cursor
VS Code
Windsurf
Claude
ChatGPT
Copilot
Gemini
Perplexity
Warp
Replit
Bolt
Lovable
Scout
Scout.app
Scout.app
AApplications
Scout installed successfully
Product
Docs
Pricing
Blog
Contact
GitHub
Running on your macOS endpoint
In short

Scout is Certiv's endpoint agent. It runs on macOS, Windows, and Linux workstations, discovers AI agents wherever they run, observes what tools they call, and supplies the Certiv Policy Engine with the context needed to block, pause, or steer an agent action before it executes. Scout is what your endpoint team installs; Certiv is what your security and IT organizations buy.

What Scout does

01

Sees every agent, whatever it runs on

Scout discovers and observes AI agent activity across your environment regardless of which platform or framework those agents run on: coding agents, browser agents, MCP servers, internal copilots.

  • One consistent view of which agents are running
  • What tools they are calling, and how sessions unfold
  • Session summaries, so you understand the work without reading raw logs

02

Captures judgment-level signal at the device

An AI agent’s full decision loop is only observable where it runs. Scout sits at the endpoint so the Policy Engine has the context it needs to reason about intent, not just match strings.

  • Full context around every agent session
  • Enables reasoning-based behavior analysis, not pattern matching
  • Findings map to the OWASP Top 10 for Agentic Applications

03

Enforces in the moment

Scout pairs with the Certiv Policy Engine so non-compliant actions are handled before they execute rather than reported afterwards.

  • Block, Pause, and Steer interventions operate in real time
  • Policy is evaluated at the moment of judgment
  • Enforcement is unchanged by who can review a session later

04

Watches agents, not people

Scout observes AI agents and agentic activity, not everything a person does on their workstation. If an AI agent is not involved, Certiv is not looking.

  • No browser history monitoring
  • No keystroke recording
  • No indiscriminate document inspection

Built for simple use and scalable management

You have heard “lightweight” too many times for the word to mean much on its own. Here is what it means operationally.

Deploys in minutes
Through the MDM you already run.
No kernel extensions
A single reboot is required.
Light footprint
Minimal CPU, unnoticeable latency.
Fails open by default
Productivity continues uninterrupted.

Agents, not employees

Security teams need visibility into AI agents. Employees need confidence that security tooling is not quietly becoming workplace surveillance. Those requirements should reinforce each other, not compete.

Scout observes AI agents and agentic activity, not everything a person does on their workstation. It does not monitor browser history, record keystrokes, or indiscriminately inspect documents. If an AI agent is not involved, Certiv is not looking.

Read about Privacy Mode
Straight Answers

What Teams Ask About Scout

Expand to view common questions.

What is Scout?
Scout is Certiv’s endpoint agent. It runs on the laptop alongside tools like CrowdStrike or Jamf, but where those watch the device and the user, Scout watches AI agents, discovering them, observing what tools they call, and capturing the context the Certiv Policy Engine needs to enforce policy before an action executes.
How is Scout different from Certiv?
Scout is what your endpoint team installs. Certiv is what your security and IT organizations buy. Scout is the endpoint agent that captures judgment-level signal at the device; the Certiv Policy Engine is the control plane that decides what is allowed, escalates or blocks what is not, and gives the CISO and CIO visibility and control.
Is Scout another endpoint agent to manage?
It is another endpoint agent, and we do not pretend otherwise. What differs is the operational lift: Scout deploys in minutes through your existing MDM, requires no kernel extensions (though it does need a single reboot), keeps CPU usage minimal with unnoticeable latency, and fails open by default so engineering workflows are never blocked by the tool itself.
Which operating systems does Scout support?
Scout runs on macOS, Windows, and Linux workstations.
Does Scout monitor employees?
No. Scout observes AI agents and agentic activity, not everything a person does on their workstation. It does not monitor browser history, record keystrokes, or indiscriminately inspect documents. If an AI agent is not involved, Certiv is not looking. Privacy Mode goes further: routine, policy-compliant agent work stays private by default, and an authorized user must record a reason to open it.

See Certiv on Your Own Endpoints

Deploy in minutes. See every agent, then control what happens next.

Book a Demo