Heading to Black Hat? Meet us at the Four Seasons! August 1-6

Runlayer Watch

Move shadow usage onto the golden path

Discover unmanaged MCPs, skills, plugins, or agents, then decide what to approve, migrate, remove, or block.

Book a Demo
Decagon
Lemonade
Gusto
Opendoor
PagerDuty
dbt Labs
Jane

See all MCPs, skills, plugins and agents in use

Scan managed devices for unsanctioned or risky AI clients, MCP connections, and skill & plugin artifacts, and agent harnesses.

Prioritize what needs action

Review each finding with its source file, detected client, exposed tools, stale artifacts, prevalence across devices, and recommended response.

Block risky shadow usage

For supported clients, Watch evaluates requests to shadow MCP servers against configured policy before they run.

Deployment and enforcement scope

Watch starts with device-based discovery, then adds enforcement where the client, user group, or risk profile calls for it.

Device coverage

Scheduled scans support macOS, Windows, and Linux, with MDM rollout guides for macOS and Windows.

Artifacts

Find agents, clients, MCPs, skills, and plugins. See source paths and risk context for each finding.

Enforcement

Control supported clients on macOS today, including Cursor, Claude Code, and Codex.

Frequently asked questions

Watch finds agents, AI clients (such as Claude Code, Codex, and Cursor), MCP servers, skills, and plugins used on managed devices. It shows what is managed, shadow, outdated, or risky.