Seats and policy
Seat the engineers who run governed agents. Access is explicit; sprawl of ungoverned laptops shrinks. Active policy rules evaluate on every agent action before tools execute—on Claude Code, Cursor, Codex, and OpenCode once those surfaces are connected.
Ownership model
- Platform / security — Own bash, path, MCP, and prompt policy for the org.
- Feature teams — Receive Relay seats and run Claude / Cursor / Codex / OpenCode under that policy without becoming security admins.
Active policy rules
Rules cover command patterns, path globs, MCP scopes, and prompt redaction. They evaluate before side effects on every agent action. Start narrow (safe scripts and repo paths), expand allowlists deliberately, and review denials in audit and replay.
Install hooks per surface under Connect surfaces.
Seats and plan limits
Relay team member counts and active policy rule limits follow your plan (Relay Only or Full Platform). See exemplar.dev/pricing .
Behavior Guards (relay_behavior_guards) are included on Starter+; Free stays off with an upsell. Entitled orgs configure detectors under Behavior Guards.
Related: Getting started, Control, Connect surfaces.