> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Hub overview

> Visibility into the AI coding agents on your fleet: what Agent Hub shows, what it deploys, and how to set it up through your MDM.

Agent Hub shows you which AI coding agents are in use across your fleet, by whom, with which tools and MCP servers, and against what data. It does this without collecting prompts, source code or file contents.

<Note>
  Agent Hub isn't enabled for every organization. If you don't see **AI agents** under **Admin → Integrations**, ask your Cimento contact.
</Note>

## How it works

A small endpoint agent, deployed through your MDM, registers as a hook with Cursor, Claude Code and OpenAI Codex. Each time one of those agents fires a hook event, the hook writes a stripped-down record (event type, tool name, agent version, timestamp) to a local buffer. Every five minutes a scheduled task posts the buffer to `api.cimento.ai`. The Agent Hub dashboard in the Cimento admin console then shows adoption, tool and MCP usage, data-access patterns and findings per person and per agent.

Read [How it works](/agent-hub/how-it-works) for the mechanics and [What data is collected](/agent-hub/data-collected) for the privacy contract.

## Supported platforms

| | macOS | Windows |
| - | - | - |
| Package | Signed and notarized `.pkg` plus a `.mobileconfig` configuration profile | Authenticode-signed Win32 app (`.intunewin`) |
| Agents | Cursor, Claude Code, Codex | Cursor, Claude Code, Codex |
| Deployment | Jamf Pro, Iru, SimpleMDM | Microsoft Intune |

## Setup at a glance

<Steps>
  <Step title="Open the wizard for your MDM">
    Under **Admin → Integrations → AI agents**, pick the card for your MDM.
  </Step>

  <Step title="Grant least-privilege access">
    You create a dedicated API role, token, key or consent with only the permissions listed on that MDM's page. Cimento performs the upload and assignment itself and never asks for your MDM administrator credentials.
  </Step>

  <Step title="Deploy to a pilot group">
    Choose a small computer group, blueprint, device group or Entra group first. Nothing is installed until you click Deploy.
  </Step>

  <Step title="Confirm egress">
    Devices need outbound HTTPS to `api.cimento.ai`. Standard proxy environment variables are honored.
  </Step>

  <Step title="Watch the rollout">
    The wizard shows per-device install status. Once devices report, they appear in the Agent Hub dashboard.
  </Step>
</Steps>

## Deploy with your MDM

<CardGroup cols={2}>
  <Card title="Jamf Pro" href="/agent-hub/deploy/jamf">
    API Role and API Client, deployed to a computer group.
  </Card>

  <Card title="Iru" href="/agent-hub/deploy/iru">
    API token with per-endpoint permissions, deployed to a blueprint.
  </Card>

  <Card title="SimpleMDM" href="/agent-hub/deploy/simplemdm">
    API key and a SAML-mapped email attribute, deployed to a device group.
  </Card>

  <Card title="Microsoft Intune" href="/agent-hub/deploy/intune">
    Entra admin consent, deployed to a security-enabled group of Windows PCs.
  </Card>
</CardGroup>

## Attribution

Telemetry is attributed to a person by the email address your MDM supplies to the device. Jamf Pro and Iru fill it from the assigned user (`$EMAIL`), and SimpleMDM from a custom attribute you map from your identity provider at enrollment. On Windows the agent reads the signed-in user's UPN. Cimento does not read your directory to do this.
