ROGUE TERMINAL v1.0 ESC to close

PLATFORM / ACCESS CONTROL

Allow AI.
Set the limits.

Approve the apps your teams need. Restrict personal accounts, control MCP tools, and remove unapproved skills.

ClaudeCompany account
Allowed
ClaudePersonal account
Restricted
DeepseekUnapproved app
Blocked
KimiUnapproved app
Blocked
Example policy Corporate accounts. Approved MCP tools.

"We allow ChatGPT" leaves a lot unanswered.

Set the account, tool, and workspace permissions behind an app approval.

01

Keep work in the company account.

An approved app can still be used through a personal account. Require your corporate workspace or tenant on supported AI services.

Block apps outside your policy and offer an approved alternative.
Scope exceptions to the teams that need them.
ACCOUNT RESTRICTION // Example
ChatGPT
Company workspace

Approved workspace ID

ALLOWED
Personal workspace

Outside the approved workspace

RESTRICTED

Corporate account controls for supported ChatGPT, Claude, Gemini, and Copilot sign-in paths.

02

Govern what your employees use.

Allow and disallow web AI. When someone opens a blocked app in the browser, they see why and how to request access instead of a silent failure.

Enforce the policy in the browser, not just at the network edge.
Every block screen links back to the rule that caused it.
BROWSER ENFORCEMENT // Example

Kimi is blocked by your organization

Blocked by your organization's AI access policy

kimi.com

Example block screen. Shown in place of the page when an app falls outside policy.

03

Approve a server. Choose its tools.

A developer needs to read pull requests. That doesn't mean their agent needs permission to delete a repository.

Block individual tools or approve the server's current tool list.
With a tool-list approval, newly added tools stay blocked until reviewed.
MCP TOOL PERMISSIONS // Engineering
GitHub MCPApproved server
Read pull requestsALLOW
Delete repositoryBLOCK
New tool after approvalOutside the approved tool listBLOCK

Example tool permissions. Enforced through supported coding-agent hooks.

04

Remove what shouldn't be installed.

A skill or hook you reject can still be sitting on a developer's machine. Send a removal action to the managed endpoint and follow the result.

Remove skills, hooks, and MCP configuration entries.
See which devices completed the action and which still need attention.
ENDPOINT REMOVAL // Example
Remove unapproved skill

Action sent to managed devices

Connected device
RemovedDevice confirmed
Offline device
PendingAwaiting reconnect

An action sent to a device stays separate from confirmed removal.

Give a team access. Keep the rule for everyone else.

Engineering needs a tool that Finance doesn't. Apply an exception to the Engineering workspace without changing access for the rest of the organization.

Enable access requests so employees can ask for a blocked app. An administrator reviews the request and chooses who gets access. The approval stays linked to the policy it creates.

workspace-exception
SAME APP // Different workspaces
  1. 01
    Allow the app

    Engineering workspace

    EXCEPTION
  2. 02
    Block the app

    Rest of the organization

    DEFAULT

The first matching rule wins. The workspace exception sits above the broader rule.

Turn findings into access decisions.

Access Control is the fourth module in the Rogue platform.

Access Control uses the Rogue browser extension, coding-agent hooks, and managed endpoint. Available controls depend on the connected integration.

Which AI tools should your teams use?