The three elements
Everything on the control plane is one of three things:Agents
The AI tools you govern (Claude Code, Cursor, VS Code, OpenCode). Each has a
name, an access key, and a policy.
Servers
The MCP servers you add. Each one exposes tools — the capabilities an
agent might use.
Grants
Controlled access from an agent to a server’s capabilities, scoped by policy.
No grant means no access.
How you operate it
Every command reads as manage an agent or control its access:A grant is a governed connection
When you grant an agent access to a server, you’re wiring a connection routed through Steerholm. The agent never talks to the server directly — it connects to Steerholm, and Steerholm forwards each call to the server only where the grant and its policy allow. The grant is the edge; Steerholm is what the traffic flows through and gets checked at. (See Architecture for how that boundary is enforced.)Bringing an agent online
Registering an agent and pointing it at Steerholm are two steps today:holm add agent <name>registers the agent and issues its access key.- You configure the agent with that key so it opens its connection to Steerholm — see Add an agent.
holm grant ...gives the agent access to the servers it should reach.
Step 2 is the current manual last mile. It’s part of adding an agent —
just not yet automated. We’re working toward Steerholm setting up that connection
for you (and launching agent sessions directly), so the copy-the-key step goes
away while the model above stays exactly the same.