GrantTap
Open account

GrantTap Enterprise

Control stays with the organization.Enforcement stays on the endpoint.

GrantTap adds a managed authorization layer to local Codex, Claude Code, Cursor, Copilot, and Grok workflows—without moving source code, prompts, or model traffic into a GrantTap control service.

  • Signed organization policy
  • Device-bound login receipt
  • Deny wins at every layer
MANAGED ENDPOINTpolicy verified
ORGANIZATIONmaximum authority
AND
COMPUTER + TASKlocal boundary
AND
PROVIDERnative approval
Effective authorityany denial wins

Implemented foundation

The security boundary is real before the dashboard is pretty.

A managed endpoint validates its enrollment, fresh login receipt, policy signature, tenant, subject, revision, and authorization epoch before local or agent approval can grant authority.

01

Protected device login

The endpoint creates its own Ed25519 identity and PKCE verifier. The QR contains only a one-time HTTPS verification URL and user code.

02

Signed policy

Organization policy is pinned to tenant, subject, issuer key, revision, expiry, and authorization epoch.

03

Fail-closed decisions

An invalid, expired, missing, or rolled-back managed policy denies managed capabilities before provider approval.

04

One machine install

The same GrantTap installation serves all supported coding agents; adapters attach to that installation instead of creating separate helpers.

Account and sign-in

Two QR paths, two separate trust boundaries.

Control plane status

No roadmap feature is presented as shipped.

Available in the current endpoint

  • Signed endpoint policy
  • Device identity + protected receipt storage
  • Deny-wins provider enforcement
  • QR-first browser approvals
  • Browser owner/admin/approver roles + one-time invitations

Next enterprise surface

  • Centralized organization directory and policy console
  • SAML/OIDC SSO and SCIM
  • Device inventory and remote revocation refresh
  • Encrypted enterprise audit delivery and compliance exports

Bring your identity provider, device fleet, and policy model. We will map the production control-plane rollout without weakening the endpoint boundary.

Contact Enterprise