---
title: "Build with AI Agents | Provide AI Agents with isolated, governed environments to safely write and test code"
description: "Coder provides AI agents with execution boundaries and task-based permissions, logs activity for traceability, and supports human–agent collaboration with RBAC."
image: "/_next/static/media/OpenGraph.37da9236.jpg"
---

![](https://coder-9oph77q2q.coderite.app/_next/static/media/server-violet.bd32a5ed.svg?w=3840)AI Governance

# Govern AI agents on infrastructure you control.

Authenticate every AI request, audit every prompt, and contain agents behind a default-deny network.

[Request demo](https://coder-9oph77q2q.coderite.app/demo)[Download solution brief](https://resources.coder.com/hub/col/resource-center/ai-governance-add-on-datasheet?pflpid=60798&pfsid=HKhWcljba2)

![Two Column Masthead Background](https://coder-9oph77q2q.coderite.app/_next/static/media/twocol-premium-masthead-bg.8b7ffea4.jpg?w=3840)![](https://coder-9oph77q2q.coderite.app/_next/static/media/ai-governance-solutions-masthead.abb750ac.jpg?w=3840)

## AI is already in your software development lifecycle. But how do you manage it?

Uncontrolled AI development tools introduce security risk, shadow usage, and rising costs, while blocking AI slows progress and delivery. With Coder, AI agents (bring your own or use Coder Agents) run on self-hosted infrastructure with enforced access controls and centralized audits of every AI interaction.

### Visibility and attribution

- Coder authenticates every AI request and ties it to a named user.
- Prompts, token usage, models, and tool invocations are logged centrally.
- Provider API keys never leave the control plane.

### Blast radius containment

- Run agents in isolated ephemeral workspaces behind default-deny networks.
- Only approved domains and services are accessible.
- Log every allow and deny centrally.

### Self-hosted control

- Deploy Coder on cloud, on-prem, or air-gapped infrastructure.
- Integrate with your IdP via OIDC and SCIM.
- Export audit events from Coder to your SIEM.

![](https://coder-9oph77q2q.coderite.app/_next/static/media/financial-institution-black.366d1b24.svg?w=3840)

> We are reliant on Coder right now to roll out Claude Code and Codex since it's the path of least resistance for centralizing model configuration.

## Get visibility and control with Coder

![AI Gateway: Govern agent interactions with LLM providers for auditing and cost control. Agent Firewall: Apply process-level enforcement to restrict and monitor agent network access. Coder Agents: Execute tasks with Coder's native agent on your infrastructure. Coder Workspaces: Run your own agents and development workflows in self-hosted environments.](https://coder-9oph77q2q.coderite.app/_next/static/media/visibility-control.6a6ca277.png?w=3840)

## Get visibility and control with Coder

- ### AI Gateway Govern agent interactions with LLM providers for auditing and cost control.
- ### Agent Firewall
- ### Coder Agents
- ### Coder Workspaces

![](https://coder-9oph77q2q.coderite.app/_next/static/media/visibility-control-no-text.cae9dc0d.png?w=3840)

## Build with tools you love

![Claude](https://coder-9oph77q2q.coderite.app/_next/static/media/claude-squircle.1ddbcdcc.svg?w=128)

![Goose](https://coder-9oph77q2q.coderite.app/_next/static/media/goose.58af7d2e.svg?w=128)

![Aider](https://coder-9oph77q2q.coderite.app/_next/static/media/aider.a575cb36.svg?w=128)

![Kiro](https://coder-9oph77q2q.coderite.app/_next/static/media/kiro.c700ea24.svg?w=128)

![Gemini](https://coder-9oph77q2q.coderite.app/_next/static/media/gemini.86c87b35.svg?w=128)

![GitHub](https://coder-9oph77q2q.coderite.app/_next/static/media/github-logo-white.cb8a80b7.png?w=128)

![OpenCode](https://coder-9oph77q2q.coderite.app/_next/static/media/opencode.972feec3.svg?w=128)

![OpenAI](https://coder-9oph77q2q.coderite.app/_next/static/media/openai-white.bf0b622e.svg?w=128)

![Auggie](https://coder-9oph77q2q.coderite.app/_next/static/media/auggie.5105add1.svg?w=128)

![Sourcegraph Amp](https://coder-9oph77q2q.coderite.app/_next/static/media/sourcegraph-amp.4f54b69a.svg?w=128)

![Cursor](https://coder-9oph77q2q.coderite.app/_next/static/media/cursor.e112be7e.svg?w=128)

![Claude](https://coder-9oph77q2q.coderite.app/_next/static/media/claude-squircle.1ddbcdcc.svg?w=128)

![Goose](https://coder-9oph77q2q.coderite.app/_next/static/media/goose.58af7d2e.svg?w=128)

![Aider](https://coder-9oph77q2q.coderite.app/_next/static/media/aider.a575cb36.svg?w=128)

![Kiro](https://coder-9oph77q2q.coderite.app/_next/static/media/kiro.c700ea24.svg?w=128)

![Gemini](https://coder-9oph77q2q.coderite.app/_next/static/media/gemini.86c87b35.svg?w=128)

![GitHub](https://coder-9oph77q2q.coderite.app/_next/static/media/github-logo-white.cb8a80b7.png?w=128)

![OpenCode](https://coder-9oph77q2q.coderite.app/_next/static/media/opencode.972feec3.svg?w=128)

![OpenAI](https://coder-9oph77q2q.coderite.app/_next/static/media/openai-white.bf0b622e.svg?w=128)

![Auggie](https://coder-9oph77q2q.coderite.app/_next/static/media/auggie.5105add1.svg?w=128)

![Sourcegraph Amp](https://coder-9oph77q2q.coderite.app/_next/static/media/sourcegraph-amp.4f54b69a.svg?w=128)

![Cursor](https://coder-9oph77q2q.coderite.app/_next/static/media/cursor.e112be7e.svg?w=128)

![Claude](https://coder-9oph77q2q.coderite.app/_next/static/media/claude-squircle.1ddbcdcc.svg?w=128)

![Goose](https://coder-9oph77q2q.coderite.app/_next/static/media/goose.58af7d2e.svg?w=128)

![Aider](https://coder-9oph77q2q.coderite.app/_next/static/media/aider.a575cb36.svg?w=128)

![Kiro](https://coder-9oph77q2q.coderite.app/_next/static/media/kiro.c700ea24.svg?w=128)

![Gemini](https://coder-9oph77q2q.coderite.app/_next/static/media/gemini.86c87b35.svg?w=128)

![GitHub](https://coder-9oph77q2q.coderite.app/_next/static/media/github-logo-white.cb8a80b7.png?w=128)

![OpenCode](https://coder-9oph77q2q.coderite.app/_next/static/media/opencode.972feec3.svg?w=128)

![OpenAI](https://coder-9oph77q2q.coderite.app/_next/static/media/openai-white.bf0b622e.svg?w=128)

![Auggie](https://coder-9oph77q2q.coderite.app/_next/static/media/auggie.5105add1.svg?w=128)

![Sourcegraph Amp](https://coder-9oph77q2q.coderite.app/_next/static/media/sourcegraph-amp.4f54b69a.svg?w=128)

![Cursor](https://coder-9oph77q2q.coderite.app/_next/static/media/cursor.e112be7e.svg?w=128)

## Move AI agents into production with Coder. Coder provides a self-hosted control plane for managing model access, agent identity, MCP tools, network egress, and audit visibility across every AI coding agent your developers use.

## Bring your own or run Coder Agents

- Run Claude Code, Codex, or any HTTP agent in self-hosted workspaces behind a default-deny network.
- Or use Coder Agents on the control plane with no separate deployment.
- Trigger agents from chat or via API for CI, GitHub Actions, Slack, and Jira.
- Identity, audit, and credentials apply consistently, so teams can switch vendors without re-architecting.

[![](https://coder-9oph77q2q.coderite.app/_next/static/media/cloud-white.0e03898d.svg?w=3840)Workspaces](https://coder-9oph77q2q.coderite.app/docs/reference/api/workspaces)[![](https://coder-9oph77q2q.coderite.app/_next/static/media/robot-white.fa896e7a.svg?w=3840)Coder Agents](https://coder-9oph77q2q.coderite.app/docs/ai-coder/agents)

![Coder Agents UI listing 5 different chats, including both Opus 4.6 Max and Haiku 4.6 models.](https://coder-9oph77q2q.coderite.app/_next/static/media/two-col-byo-agents.8bb49d1f.jpg?w=3840)

## Get centralized visibility and auditability

- Coder's AI Gateway centralizes access for coding agents like Claude Code and Codex.
- Centralize authentication, user-level tracking, cost monitoring, and audit trails across all developer laptops.
- Enable compliant AI adoption without slowing developers down.

[![](https://coder-9oph77q2q.coderite.app/_next/static/media/server-white.94bdf50c.svg?w=3840)AI Gateway](https://coder-9oph77q2q.coderite.app/docs/ai-coder/ai-gateway)

![Product UI to manage AI usage for your organization in Coder Workspaces. Information about each logged agent includes initiator, prompt, tokens, and model.](https://coder-9oph77q2q.coderite.app/_next/static/media/two-col-visibility-and-audibility.1e6e43cb.jpg?w=3840)

## Restrict AI agent access by default

- Coder's Agent Firewall enforces default-deny network policies, restricting which domains and HTTP methods agents can access.
- Admins define explicit allow lists in templates controlling access to registries, internal services, and external APIs.
- All policy decisions are logged and streamed to the control plane for centralized auditing.

[![](https://coder-9oph77q2q.coderite.app/_next/static/media/padlock-white.5b4e6a27.svg?w=3840)Agent Firewall](https://coder-9oph77q2q.coderite.app/docs/ai-coder/agent-firewall)

![Developer permissions: Repository controls, Network access, Filesystem access. Coding Agent permissions: Allow outbound HTTP/HTTPS to allowlisted domains, Block unproxied access via namespace isolation, Optionally forward audit logs to coderd](https://coder-9oph77q2q.coderite.app/_next/static/media/two-col-restricted-agent-access.6fa5ea33.jpg?w=3840)

![Gradient Background](https://coder-9oph77q2q.coderite.app/_next/static/media/stat-slider-bg.6cb15c83.jpg?w=3840)

From Day 30 to Day One: How a Global FinTech Is Modernizing Developer Onboarding for 15,000+ Engineers

[Read the case study](https://coder-9oph77q2q.coderite.app/success-stories/financial-services)

![Fortune 500 Financial Technology logo](https://coder-9oph77q2q.coderite.app/_next/static/media/financial-technology-white.6bd211ec.svg?w=3840)

## Related content

## Related content

[![Datasheet: AI Governance Add-On](https://coder-9oph77q2q.coderite.app/_next/static/media/ai-governance-datasheet.60bbbcb5.png?w=3840)
Datasheet

### AI Governance Add-On

See more](https://resources.coder.com/hub/col/resource-center/ai-governance-add-on-datasheet?pflpid=60798&pfsid=HKhWcljba2)[![Inside the Stack: Secure and Scale AI Coding Agents with Coder](https://www.datocms-assets.com/19109/1764963037-blog_inside-the-ai-stack.png?w=3840)
Blog

### Inside the Stack: Secure and Scale AI Coding Agents with Coder

See more](https://coder-9oph77q2q.coderite.app/blog/inside-the-stack-secure-and-scale-ai-coding-agents-with-coder)[![How Credit Karma Accelerated Secure, Compliant, and Scalable Data Workflows with Coder. November 12 at 10:00AM PT](https://www.datocms-assets.com/19109/1761314296-creditkarma-webinar-lp-thumbnail.png?w=3840)
Webinar

### How Credit Karma Accelerated Secure, Compliant, and Scalable Data Workflows with Coder

See more](https://resources.coder.com/hub/col/resource-center/credit-karma-data-workflows)[![State of Development Environments 2025](https://coder-9oph77q2q.coderite.app/_next/static/media/state-of-dev-envs.e2d5908f.png?w=3840)
Whitepaper

### State of Development Environments 2025

See more](https://resources.coder.com/hub/col/resource-center/state-of-development-environments?pflpid=60798&pfsid=HKhWcljba2)

## FAQs

Is Coder compliant with regulations like GDPR or DORA?

Coder helps you meet compliance goals by running entirely within your own infrastructure. This means your data stays where you control it—critical for meeting FedRAMP, GDPR, DORA, and similar requirements.

Is Coder SOC 2 Type II certified?

Does Coder work with my existing tools?

How does Coder support compliance in highly regulated industries like banking?

What IDEs and languages are supported?

Is Coder secure enough for regulated industries?

Can I use Coder with AI coding agents or ML workloads?
