Surfil
// By persona

One interception layer under every agent you support

Standardize agents the way you standardize everything else: one on-device layer, byte-exact, that every product plugs into - never a second proxy to run.

surfil · where it sits in your stack
Claude CodeCursorCodexCopilotMCP
↓ one adapter each
◈ Surfil interception layer
↓ byte-exact passthrough
your provider / model
The job: When I standardize developer tooling, I want agents on one governed layer, so I can support them without operating another gateway.
How it works

What you turn on

You provide the paved road for hundreds of developers, and agents showed up on it faster than you could pave a governed lane for them.

1

One layer for all agents

Claude Code, Codex and MCP route their traffic through a single on-device point; editors like Cursor connect via MCP.

2

Registry and discovery

Fleet Control inventories every enrolled device and surfaces the agents that nobody ever declared.

3

Policy as a code path

Compose Guard and Fleet rules into versioned packs, simulate them, and stage enforcement by device group.

First signed receipt: A device registry with shadow-agent discovery and staged policy previews.
What holds

Why it fits the paved road

No stacking tax

Every product is a stage on the same stream, so adding a capability never adds a hop or a failure surface.

Flat, stateless edge

Devices do the work and the edge stays stateless, so cost stays flat as your developer count grows.

Reversible by design

Every agent config restores byte-for-byte on uninstall, so adopting the layer is never a one-way door.

By persona

More in this view

Same spine, a neighbouring starting point.

Not the right lens? The same eleven paths are also organized by team size, by problem, and by persona on the solutions overview - pick whichever matches how you think.

Turn on the first stage today

The install is reversible byte-for-byte, and the first signed receipt arrives after one normal week of traffic.