Before you start
- Open the Failproof AI dashboard and create an account or sign in with your work email.
- Go to Administration → Keys and create a key with
events:add and policies:pull. If you plan to use Jev through FailproofAI Cloud, choose the machine preset, which also grants jev:evaluate.
- Copy the one-time secret, then read it into a shell on the target machine.
read -s takes it at a prompt that does not echo, so it never appears in a command:
Install
Install and connect Failproof AI
That one command is the whole of setup: it installs the local daemon (root once), wires hooks into every agent CLI it finds, and connects this machine to Cloud. Passing the key through the environment rather than --token keeps it out of ps, where every user on the machine can read a command’s arguments. It does not keep it out of shell history — reading it with read -s is what does that. In CI, inject it as a masked secret and keep shell tracing (set -x) off, or the trace prints it.Session transcripts are sent by default. Add --no-transcripts to report hook activity and policy decisions without transcript content.Do not reach for failproofai config --connect <url> here. That flag enrols a machine that is already set up and returns straight after — no daemon, no hooks — so the machine would appear in Cloud while collecting and enforcing nothing.
If this machine already has agent history, preview and import the last seven days, then wait for delivery to finish. Skip this step on a new machine.Open Sessions in Failproof AI and select an imported session. Attach Failproof AI to a harness
The previous step already wired every agent CLI it detected. Re-run it for one harness explicitly when you need to, or to add a harness installed afterwards. Every one of the 12 is a valid --cli value — claude, codex, copilot, cursor, opencode, pi, hermes, openclaw, factory, devin, antigravity, goose.Blocking a tool call before it runs is verified on all 12. Turn-end gates are verified on 8 — see enforcement capability for the per-harness matrix. Choose what to enforce
Wiring hooks enables no policy. Setup deliberately picks none — that decision is yours — so take a pack:The pack is fetched from its GitHub release, checksum-verified, and pinned to the exact tag it resolved. It carries 39 policies and switches on the 10 its manifest marks as safe to enable unattended. Use them to see local policy decisions and try enforcement before Failproof AI audits your sessions and writes policies for your agents.Read any pack before taking it with failproofai policies show <owner>/<repo>, and see policy packs for taking only part of one.Until this runs, the only thing enforcing is block-failproofai-commands — the always-on guard that stops an agent switching Failproof AI off. failproofai policies lists what is on. Audit the behavior
Follow Run your first failure check. Use a concrete goal such as “find sessions where the agent retried a failing tool without changing its approach.” Run failproofai config --status. A healthy setup reports the cloud connection, daemon state, and whether enforcement is paused.