Quickstart

Get the Prismor runtime guard protecting your AI coding agent in about five minutes: install, run the setup wizard, enroll this machine, hook your agent, and verify it's working.

This walks through prismor, the runtime guard that watches your AI agent. If you're looking for the repo/SBOM vulnerability scanner instead, that's the separate prismor-cli tool — see the CLI docs.


1. Check prerequisites

python3 --version   # need >= 3.8
pip3 --version
python3 -c "import yaml"   # PyYAML — required by the policy engine

If import yaml fails, install it first: pip3 install pyyaml.

2. Install

curl -sSL https://prismor.dev/install | sh

Or with pip directly:

pip install prismor

3. Run the setup wizard

prismor setup

This is an interactive wizard: pick enforcement mode, choose a governance mode or which rules block, select which agents to hook, enable secret cloaking, pick which login (if any) judges uncertain events, choose install scope (this project vs. global), and optionally set an unlock password for the agent self-edit window.

Two modes, two philosophies:

  • Observe reports everything and blocks nothing, so setup leaves every rule on. This is the right first install.
  • Enforce first offers three named governance modes (dev-safe, trusted-workspace, regulated-airgap) or custom. Choose custom to pick rules one by one: it starts with nothing selected — including the safety floor, which is marked recommended rather than assumed. Nothing blocks until you choose it (press a to take the recommended set). Your selection is written to .prismor/policy.yaml one line per rule, so what blocks is readable in the file, and every block prints the exact prismor allow … command that makes a narrow exception. Prismor's own self-protection rules are the one thing not on the menu — they always block, because they are what stops an agent editing this selection.

For CI or scripted environments, skip the prompts:

prismor setup --non-interactive --mode observe
# or, enforcing with the recommended block set:
prismor setup --non-interactive --mode enforce --recommended
# or an explicit set:
prismor setup --non-interactive --mode enforce --enforce-rules destructive-command,secret-exfiltration

4. Enroll this device

If your team uses the Prismor dashboard, enroll this machine so it reports to your org's policy. Get a one-time enrollment token from Dashboard → Getting Started checklist → Enroll device (or the Agent Monitoring tab), then:

prismor enroll <token>

The token is single-use and expires in 24 hours. Skip this step if you're only running Prismor locally with no org.

5. Hook your agent

Wire Prismor into your coding agent. Start in observe mode — it logs every tool call without blocking anything, so you can see what the policy would do before it does it:

prismor install-hooks --agent claude --scope project --mode observe

Swap claude for cursor, windsurf, codex, copilot, openclaw, hermes, grok, kiro, crush, openhands, qwen, continue, goose, or all to hook every agent found in the workspace. This must be run from inside the project directory you want protected — --scope project writes the hook registration into that workspace's agent settings (e.g. .claude/settings.json for Claude Code), not a global config.

Hooking Codex? Codex won't run a hook until you trust it: open codex interactively once in the workspace and accept the hook-trust prompt. Until then nothing is screened (prismor status and prismor doctor flag untrusted hooks).

Once you've reviewed a day or two of logs and trust the policy, switch to blocking:

prismor install-hooks --agent claude --scope project --mode enforce

6. Verify it's working

prismor dashboard   # opens http://127.0.0.1:7070

Run a normal session with your agent, then check the dashboard — you should see tool calls appearing as events. If it's empty, you haven't run an agent session in a hooked workspace yet (see Troubleshooting).

If you enrolled the device in step 4, also confirm it shows up under Dashboard → My Policy with a recent check-in.


Next steps

Frequently asked questions

How long does it take to set up Prismor?

About five minutes. The quickstart walks through six steps: check prerequisites, install, run the setup wizard, enroll the device, hook your agent, and verify it is working.

What are the prerequisites for installing Prismor?

Python 3.7 or newer, pip3, and PyYAML, which the policy engine requires. If importing yaml fails, install it with pip3 install pyyaml before continuing.

What is the difference between prismor and prismor-cli?

prismor is the runtime guard that watches your AI coding agent and inspects tool calls before they execute. prismor-cli is a separate tool that scans repositories for vulnerabilities and secrets and generates an SBOM.

Do I need to enroll a device and install hooks separately?

Yes. Enrolling reports the device to your organization, but agent activity only appears after you run prismor install-hooks. They are two distinct steps in the quickstart.