| Cage | The gateway, on the request path | A base URL, set by one command | Yes | Yes, exportable; policy changes are hash-chained | No |
| Claude Code managed settings and hooks | The client | Nothing extra; policy arrives by MDM, a file or the claude.ai console | Claude Code only | OpenTelemetry tool_decision events, with their source; you run the collector | Yes |
| Codex requirements | The client and its OS sandbox | Nothing extra | Codex only | OpenTelemetry codex.tool_decision events, once you opt in | Yes |
| CC Safety Net (MIT) | A hook in each client | A hook, per client | Both supported, a hook in each; policy shared through git | Command decisions, on the machine | Not stated |
| dcg (a custom license based on MIT, with an OpenAI/Anthropic rider) | A hook in each client | A binary and a hook, per client | Both supported, a hook in each | warn and log rules record decisions | An ask rule, "where the hook protocol supports it" |
| Lasso | Client hooks, with scanning in Lasso's cloud | Hooks, rolled out with managed settings | Both named | Audit trail | Not stated |
| Zenity | Hooks on the machine, and an MCP gateway | Hooks | Both named, one central policy | Through hooks and OpenTelemetry | Not stated |
| Prisma AIRS | Endpoint, network and cloud, plus an AI gateway | Depends on the part you deploy | Both named, one policy | Session timelines | An exception request |
| LiteLLM tool permission guardrail | A proxy you host, on the request path | A base URL | Yes, regex rules on tools and arguments | Not stated on the guardrail page | No |
| Docker Sandboxes | A microVM with a network proxy | The sbx CLI and a microVM | Both named; network policy only | Not stated | No |