Put your agent behind the glass.
Guard mode wraps any stdio MCP server your agent uses. Pick your setup below and copy its config. Each tab shows the timeout to raise and how a held call behaves with that client. Setups marked "documented, not yet tested" follow the client's own documentation; we have not run them with the guard yet. Compatibility lists which are tested.
1. Your setup
Desktop app · documented, not yet tested
Config: macOS: ~/Library/Application Support/Claude/claude_desktop_config.json; Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"files-guarded": {
"command": "npx",
"args": ["-y", "@costrinity/vitna-compliance-mcp", "guard", "--", "npx", "-y", "@modelcontextprotocol/server-filesystem", "/path/to/folder"],
"env": {
"VITNA_OWNER_ID": "<your VITNA owner id>",
"VITNA_API_KEY": "<your VITNA API key>",
"VITNA_GUARD_POLICY": "/path/to/policy.json"
}
}
}
}- Tool-call timeout: 240 s (seen in user logs, not documented). It has no setting to raise.
- Holds: the guard waits for the decision while this client is still waiting.
- Claude Desktop cancels a tool call after 240 s and has no setting to raise it, so the guard waits up to 235 s. Its Code tab and Cowork use a different client name, which the guard treats as unknown.
Anything your agent can reach outside VITNA, like a built-in shell, is outside the glass.
Sources: modelcontextprotocol.io, github.com, github.com
2. A policy
Without a policy file there are no holds: each call gets a preflight check. Save one of these as policy.json and point VITNA_GUARD_POLICY at it.
Hold deletes
For the reference filesystem server, which has no delete tool: overwriting, editing and moving are how it destroys files. Use your server's own tool names.
{
"allowed_actions": [
"*"
],
"hold_actions": [
"write_file",
"edit_file",
"move_file"
]
}Hold payments and exports
Example tool names. Replace them with the names your server lists.
{
"allowed_actions": [
"*"
],
"hold_actions": [
"create_payment",
"send_payment",
"refund_payment",
"export_data"
]
}Custom
List the tools to hold. Tools not listed are allowed; a hold that nobody decides is blocked.
{
"allowed_actions": [
"*"
],
"hold_actions": []
}3. What it covers
Anything your agent can reach outside VITNA, like a built-in shell, is outside the glass. Turn your agent's built-in tools off if you want every action to go through the guard. The session record lists what you declared as unwrapped. Detection is heuristic pattern matching, not a sandbox.