Skip to main content
Steerholm is one surface with two faces. To your AI agents it’s an action plane — the single place they connect to and act. To you it’s a control plane — where you decide what every agent can reach and do, down to the individual action and its arguments. Nothing runs that you didn’t allow. New here? Install Steerholm, then the quickstart gets you to a scoped agent in minutes. For the full mental model, see the control plane.
Steerholm// ACTION PLANE
Claude Code
Cursor
Zed
VS Code
filesystem
git
database
shell
▸Claude Code→database
ACCESS POLICY(reaches 2/3 available tools)
R
W

Agents and their servers connect through Steerholm. Every connection carries a policy you set — which tools, which arguments — and defaults to deny.

Why it exists

Today each agent configures its own MCP servers, with no shared management and no way to limit what an agent can do once it’s connected. Steerholm brings them onto one plane you control: agents act in one place, and every action is checked against your policy before it reaches a server.

Agents, servers, and grants

Agents

The AI tools you govern — Claude Code, Cursor, VS Code, OpenCode. Each has a name, an access key, and a policy.

Servers

The MCP servers you add. Each one exposes tools — the capabilities an agent might use.

Grants

Scoped access from an agent to a server’s tools — per tool, per argument. No grant means no access.
Two things you add — agents and servers — and one governed connection you grant between them. See Permissions for the tool and argument syntax.

Set it up in three moves

1

Add a server

Register an MCP server once; the daemon starts and supervises it.
2

Add an agent

Register an agent and get its access key — the credential it connects with.
3

Grant scoped access

Give the agent exactly the tools it needs, down to the argument.
Then point the agent at http://127.0.0.1:4767/mcp with its access key — see Add an agent. It sees only the tools its policy allows.