What it does
- Credential isolation keeps secrets away from agents; tokens are injected only at tool invocation.
- The egress inspection plane logs every outbound request with under 4ms network overhead and can allow, pass through, or deny calls.
- Per-verb tool policies let you allow or deny specific commands, such as allowing aws s3 cp and denying aws s3 rm.
- Block-first gating stops risky actions until a human justifies them, with live approvals.
- An admin can stop any Space in the org at once; the pod is torn down but its volume persists for inspection or resume.
- It is agent-agnostic, so you can bring any CLI-callable coding agent via manifest, with eight agents supported out of the box.
Pricing
Marshal is in a private beta by invitation, with no public pricing listed.
Good to know
- Runs inside your VPC on Kubernetes, using your cluster and your KMS.
- The client daemon works on Linux laptops and integrates with terminals, VS Code, Cursor, and browsers.
- Spaces can be paused and resumed with zero compute while paused.
Questions
- Can I stop a running Space without losing work?
- Yes. An admin can stop any Space; the pod is torn down but its volume is preserved for later resume or inspection.
- What happens if an agent tries a destructive database command?
- The database control plane blocks the statement per policy, for example deny DROP, and logs the attempt.
- Do I need to restart agents to apply new policies?
- No. Policies can be revoked or changed live on a running Space without a restart.
In their words
Coding agents at full speed. With full receipts.
Every byte, every verb, every credential, logged.