Skip to main content

The endpoint daemon

This section is the reference for operating lumen-agent directly on a machine: its command line, its two config files, the YAML policy format, the local inspection API, and the findings it writes to disk.

Most people never need this section

The console is how an organization reads its AI activity, writes policy and runs its fleet. A machine is enrolled from the console, takes its policy from the console, and reports its findings to the console. If that is your deployment, start with Get started and The console — you never have to touch a command line.

Reach for the pages here when you self-manage the binary: running the agent offline or locally without a control plane, debugging why a machine has recorded nothing, editing a policy file on a machine that was never enrolled, or integrating something on the host with the local inspection API.

What runs on the device​

lumen-agent is a single static Go binary that runs as an OS service (systemd, launchd or SCM) with zero inbound ports. It is described in full, as a collector, in Endpoint agent. In one line: it inspects, captures and enforces locally, spools findings to disk, and drains them to the cloud over outbound-only HTTPS.

The local vs cloud split​

The agent is a connected service by design. run refuses to start without a cloud.url, because an agent with no control plane inspects and enforces but is invisible in the console. Running without one is a deliberate choice you state — --local-only, or mode: local in the config's cloud section — not a default you fall into. That local mode is what the CLI examples throughout this section use, and it is how the detection checks run on a laptop with no account.

The pages in this section​

PageWhat it covers
CLI referenceEvery lumen-agent command and the flags worth knowing
Configurationagent.yaml and policy.yaml, both hot-reloaded
Policy file formatThe YAML policy grammar, the access/prompt-rule model, and validating a file
Reading findings on the endpointstatus, the on-disk findings.jsonl, and the queries that tune a policy before you enforce
Local APIThe loopback inspection contract other tools on the machine call
Local proxy & autoconfigHow the agent captures traffic itself, and points the machine's AI tooling at it
Service lifecycleInstall, upgrade, disable and remove the OS service