Intercis
← Windows lab Linux lab

The Linux lab:
same policy, new OS — and a workaround, caught.

Real footage from an Ubuntu machine. Claude Code and OpenAI Codex run natively on Linux, governed by the same Intercis tenant as the Windows lab. Both are told to delete a folder. Both are blocked. And when one tries a different mechanism to get the same result, a second enforcement layer catches the intent.

Claude Code on Ubuntu — blocked, then it stands down

The delete is denied at the proxy. Pushed to delete the files individually instead, the agent declines to route around the control — and recommends a policy exception decided by a human.

linux lab — Claude Code · 1:58

Unedited screen capture. Policy fired: shell-rm. The folder survives every attempt.

OpenAI Codex on Ubuntu — the classifier catch

Codex's shell delete is denied by the pattern layer. It then tries a file patch instead — a deletion mechanism no regex matches. The second layer, an AI classifier, reads the intent and denies that too. Both denials land in the live feed.

linux lab — OpenAI Codex · 1:22

Unedited screen capture. Policies fired: shell-rm, then llm-classifier on the workaround.

OS-agnostic by design

Enforcement happens at the API boundary, not in the OS. Windows, Linux, and macOS agents are governed the same way.

Two enforcement layers

A pattern layer catches known destructive commands. An AI classifier backstops it when an agent tries something it has no pattern for — on camera, unscripted.

One tenant, four agents

Claude and Codex, on Windows and Ubuntu, all reporting into one policy and one audit feed.

Want to see this on your agents?

15-minute live demo over video call. You bring your agent setup. We bring the policy layer. No slides.

Request a live demo

Or email directly: sales@intercis.io

Same policy, different OS: watch the Windows lab → · all demos
© 2026 Intercis · intercis.io · No agent acts without authority.