
Forge policy enforcement for coding-agent traffic
Support
Support is capability-specific. Inventory coverage does not imply that every
model API, MCP transport, or response format is available for content-aware
enforcement.
Routing
Use one or both routing paths:
Agentless network routing uses managed TLS inspection for the supported
content-aware destination set. Forge for devices provides the same gateway path
without modifying the coding agent or installing a Forge adapter inside it.
Sessions
Forge reconstructs coding-agent sessions from routed model and MCP traffic. A session preserves the user or workload identity, device or network source, client and provider, native request identifiers, policy decisions, latency, and upstream outcome.
Content visibility follows the selected privacy mode and the capability of the
protocol being routed. Forge records metadata-only traffic as metadata-only; it
does not present it as inspected content.
Policies
The gateway evaluates the same Forge policy model used across other controlled AI surfaces:
Access policies govern which agents, models, providers, destinations, MCP
servers, and tools an identity may use. Content policies govern the data and
actions inside an allowed interaction.
Inventory
Device, repository, SaaS, and cloud collectors can discover coding-agent configuration independently of routed activity:
Hooks in Inventory are customer or product artifacts Forge discovered. Forge
does not install them to secure the agent.