---
title: Canyon Road — Execution-Layer Security for AI Workloads
description: Control what AI can access, run, and connect to — at runtime. Supervised copilots on endpoints. Unsupervised agents everywhere else. One control plane.
doc_version: 1.0
last_updated: 2026-05-22T16:45:01.455Z
canonical: https://www.canyonroad.ai/
---

# Canyon Road — Execution-Layer Security for AI Workloads

Control what AI can access, run, and connect to — at runtime. Supervised copilots on endpoints. Unsupervised agents everywhere else. One control plane. Local enforcement.

## What Canyon Road does

- **Control what matters.** Allow, prompt, block, or redirect — by destination, command, tool, or workload.
- **See everything.** Every AI-triggered connection, command, and file change, fleet-wide.
- **Prove it happened.** Audit trails, SIEM export, and an emergency brake when you need it.
- **Steer, don't just block.** Redirect to approved registries and endpoints so work keeps moving.

## Two execution contexts

Canyon Road governs both supervised AI on endpoints and unsupervised agents in automation, with the same runtime control surface.

### Supervised AI on endpoints — Beacon

Copilots and desktop tools (Claude, Cursor, ChatGPT) run with employee credentials. Beacon adds guardrails and approvals to keep endpoints productive and safe. See [Beacon](https://www.canyonroad.ai/products/beacon/).

### Unsupervised agents anywhere — AgentSH

Headless agents execute fast with no user to prompt. AgentSH enforces least privilege at the syscall level — in CI, containers, pipelines, and dev environments. See [AgentSH](https://www.canyonroad.ai/products/agentsh/).

### Centralized control — Watchtower

Watchtower distributes policy, routes approvals, exports to your SIEM, and provides a fleet-wide kill switch. See [Watchtower](https://www.canyonroad.ai/products/watchtower/).

## Why now

- **It's on endpoints.** Developers installed Claude, Cursor, ChatGPT. IT did not provision it. Security cannot see it.
- **It's moving into automation.** Agents are being added to CI, pipelines, ops, and internal workflows. No UI. No supervision. Full blast radius.
- **Blocking does not work.** Users route around walls. You need guardrails that steer toward approved workflows and enforce least privilege.

## FAQ

**What's the difference between Beacon and AgentSH?** Beacon secures supervised AI on endpoints. AgentSH secures unsupervised agents wherever they run — CI, containers, pipelines, and dev environments.

**What does Watchtower do?** Watchtower is the command center. It distributes policy, routes approvals, exports to SIEM, and provides a fleet-wide kill switch. Beacon and AgentSH enforce locally at execution time.

**What do you mean by "steer"?** Steering redirects AI to approved alternatives. It keeps users productive and prevents retry loops that happen when agents keep hitting a hard block.

More on the [FAQ page](https://www.canyonroad.ai/faq/).

## Glossary

- **Execution-layer security** — controls applied at the moment of AI-triggered execution (a syscall, a network connection, a tool call), as opposed to network or identity controls. See the [Execution-Layer Security primer](https://www.canyonroad.ai/execution-layer-security/) and the full [terminology page](https://www.canyonroad.ai/execution-layer-security/#terminology).
- **Steer** — redirect an AI request to an approved alternative instead of hard-blocking it.
- **Supervised vs. unsupervised AI** — supervised: a human in the loop on the endpoint. Unsupervised: an agent running headless in CI or a pipeline.

## Get started

- Install AgentSH — open source: <https://www.agentsh.org/#quickstart>
- Talk to us — enterprise onboarding, Beacon, or Watchtower: [contact](https://www.canyonroad.ai/contact/)
- Email: <hello@canyonroad.ai>

## Sitemap

- [Home](https://www.canyonroad.ai/)
- [How it works](https://www.canyonroad.ai/how-it-works/)
- [Execution-Layer Security](https://www.canyonroad.ai/execution-layer-security/)
- [Use cases](https://www.canyonroad.ai/use-cases/)
- [FAQ](https://www.canyonroad.ai/faq/)
- [Contact](https://www.canyonroad.ai/contact/)
- [agentsh](https://www.canyonroad.ai/products/agentsh/)
- [Beacon](https://www.canyonroad.ai/products/beacon/)
- [Watchtower](https://www.canyonroad.ai/products/watchtower/)
- [Blog](https://www.canyonroad.ai/blog/)
- [Full sitemap (markdown)](https://www.canyonroad.ai/sitemap.md)
- [Full sitemap (XML)](https://www.canyonroad.ai/sitemap.xml)
