The endpoint daemon
This section is the reference for operating lumen-agent directly on a
machine: its command line, its two config files, the YAML policy format, the
local inspection API, and the findings it writes to disk.
The console is how an organization reads its AI activity, writes policy and runs its fleet. A machine is enrolled from the console, takes its policy from the console, and reports its findings to the console. If that is your deployment, start with Get started and The console — you never have to touch a command line.
Reach for the pages here when you self-manage the binary: running the agent offline or locally without a control plane, debugging why a machine has recorded nothing, editing a policy file on a machine that was never enrolled, or integrating something on the host with the local inspection API.
What runs on the device
lumen-agent is a single static Go binary that runs as an OS service (systemd,
launchd or SCM) with zero inbound ports. It is described in full, as a
collector, in Endpoint agent. In one line: it
inspects, captures and enforces locally, spools findings to disk, and drains
them to the cloud over outbound-only HTTPS.
The local vs cloud split
The agent is a connected service by design. run refuses to start without a
cloud.url, because an agent with no control plane inspects and enforces but is
invisible in the console. Running without one is a deliberate choice you state —
--local-only, or mode: local in the config's cloud section — not a default
you fall into. That local mode is what the CLI examples throughout this section
use, and it is how the detection checks
run on a laptop with no account.
The pages in this section
| Page | What it covers |
|---|---|
| CLI reference | Every lumen-agent command and the flags worth knowing |
| Configuration | agent.yaml and policy.yaml, both hot-reloaded |
| Policy file format | The YAML policy grammar, the access/prompt-rule model, and validating a file |
| Reading findings on the endpoint | status, the on-disk findings.jsonl, and the queries that tune a policy before you enforce |
| Local API | The loopback inspection contract other tools on the machine call |
| Local proxy & autoconfig | How the agent captures traffic itself, and points the machine's AI tooling at it |
| Service lifecycle | Install, upgrade, disable and remove the OS service |