Start with the workflow the team wants to keep
Pick a repository where developers use Claude Code for a concrete task, such as a reviewed code change. Write down the permitted files, commands and MCP tools and assign a developer platform owner. That inventory is the denominator for rollout coverage; the number of installed machines is not enough.
Use the existing Claude Code security and hook walkthroughs for technical boundaries. This playbook addresses the operational decision: which cohort can use the tool, who owns exceptions and what evidence allows the next cohort to join.
Split responsibilities before distributing configuration
Security reviews passport scope and policy exceptions. Developer platform validates host versions and the loaded hook. Repository owners choose protected paths and required checks. IT manages fleet installation and removal. Give each owner a review date and a rollback action.
Choose local or hosted verification deliberately. Hosted Team use adds signed decisions and organization audit. A local evaluation can support developer testing, but its output does not establish hosted persistence.
Validate the session after installation
Use the supported framework setup command below and inspect the generated configuration. Restart the host as the guide requires. In the active session, verify a harmless allowed operation and a prohibited fixture; retain both policy results and tool effects.
Warn mode can continue a denied action. Enforcement must stop it at the intended point. Keep untested tools and editable configuration boundaries in the pilot record rather than inferring protection from a successful installer.
Review exceptions with developers
When a legitimate task is denied, capture the governing policy and required scope change. Have the policy owner approve an adjustment and rerun the allowed and denied cases. Avoid broadening the passport to silence findings without reviewing the new authority.
Add GitHub Repository Guard separately for changes reaching the repository. Review report-only findings before requiring its enforcement check through branch rules. Runtime checks and repository review remain complementary.
Expand using the pilot record
Compare useful work completed, unresolved findings and tested coverage with the cohort's original inventory. Expand only the hosts and workflows you have reviewed. For managed devices, use the enterprise deployment guide and validate repeat deployment, repair and approved removal on the test group first.
The next cohort should receive the same policy owner, escalation route and review schedule. A Team subscription suits shared hosted enforcement and audit; a broader IT and security deployment should begin with an Enterprise rollout conversation.
Prepare the pilot setup
npx @aporthq/aport-agent-guardrails claude-code
npx @aporthq/aport-agent-guardrails mode claude-code --enforcement=warnFollow the linked framework guide to verify the actual host session.
Product and implementation sources
Choose your rollout path
Team uses organization billing and Stripe Checkout. Enterprise starts with a rollout call to agree the deployment scope.
Install my guardrail