Agent Hub isn’t enabled for every organization. If you don’t see AI agents under Admin → Integrations, ask your Cimento contact.
How it works
A small endpoint agent, deployed through your MDM, registers as a hook with Cursor, Claude Code and OpenAI Codex. Each time one of those agents fires a hook event, the hook writes a stripped-down record (event type, tool name, agent version, timestamp) to a local buffer. Every five minutes a scheduled task posts the buffer toapi.cimento.ai. The Agent Hub dashboard in the Cimento admin console then shows adoption, tool and MCP usage, data-access patterns and findings per person and per agent.
Read How it works for the mechanics and What data is collected for the privacy contract.
Supported platforms
Setup at a glance
1
Open the wizard for your MDM
Under Admin → Integrations → AI agents, pick the card for your MDM.
2
Grant least-privilege access
You create a dedicated API role, token, key or consent with only the permissions listed on that MDM’s page. Cimento performs the upload and assignment itself and never asks for your MDM administrator credentials.
3
Deploy to a pilot group
Choose a small computer group, blueprint, device group or Entra group first. Nothing is installed until you click Deploy.
4
Confirm egress
Devices need outbound HTTPS to
api.cimento.ai. Standard proxy environment variables are honored.5
Watch the rollout
The wizard shows per-device install status. Once devices report, they appear in the Agent Hub dashboard.
Deploy with your MDM
Jamf Pro
API Role and API Client, deployed to a computer group.
Iru
API token with per-endpoint permissions, deployed to a blueprint.
SimpleMDM
API key and a SAML-mapped email attribute, deployed to a device group.
Microsoft Intune
Entra admin consent, deployed to a security-enabled group of Windows PCs.
Attribution
Telemetry is attributed to a person by the email address your MDM supplies to the device. Jamf Pro and Iru fill it from the assigned user ($EMAIL), and SimpleMDM from a custom attribute you map from your identity provider at enrollment. On Windows the agent reads the signed-in user’s UPN. Cimento does not read your directory to do this.