Using Coco
The guide for the person who installed it and now has to live with it.
Using Coco
The work is not installing Coco, which takes one command. The work is deciding what this team's rules actually are and writing them down so a machine can hold the agent to them.
Do that with the people who own the rules, not for them. A contract nobody in the room can read is a contract nobody will defend when it blocks something.
The first week
Stay in observe mode. It is the default and the reason is practical. A guardrail that blocks legitimate work on its first morning gets uninstalled by lunchtime, and the contracts have not been tested against this team's actual work yet.
Work normally. Then read the report.
coco reportCatch report
3 decisions, 3 would not have passed enforce mode
BLOCK session.credential_then_egress/no_egress_after_credential_read x1
This session has already read a credential file, and this call sends
data off the machine
https://status.example.com
ESCALATE baseline.credential_access/credential_read_needs_a_person x1
The agent is reading a file that holds a credential
/tmp/.envThe report groups everything enforcement would have stopped by the contract that stopped it, with examples from your own traffic. Read it three ways.
- A rule firing constantly on ordinary work is drafted wrong. Loosen it. This is the common finding in week one and it is not a sign anyone is careless.
- A rule that never fired is either well drafted or dead. Check which by asking whether the work it governs happened at all.
- A rule that caught something that genuinely should not have happened is your argument for enforcement. Name those examples when you make the case.
A team that cannot produce that report should not be enforcing yet.
Finding out what is worth governing
Three questions, and wait for real answers.
Which action, if the agent got it wrong, would you have to tell someone about? That is the action worth a contract, and everything else is noise.
What has to be true before that action is allowed? Push until the answer names a fact that exists somewhere on disk or in a system rather than a feeling. "Step 0 is done" becomes "the Step 0 report and five search screenshots are in the case folder".
Who decides when the answer is unclear? That person is who ESCALATE goes to.
If the team has a policy document, a runbook or a procedure, read it. Rules that already exist and are already agreed beat rules invented in the conversation. See Drafting from a policy.
Which pages apply to which option
Most of this section is the same on both roads, because both run the same gate against the same contract format. Three pages differ.
| Page | npx | SDK |
|---|---|---|
| CLI reference | Yes | The gate's own commands run where the gate runs |
| The dashboard | Not installed | Yes |
| Modes | A config file | An environment variable |
Contracts, the mandate, state, escalations and the ledger read the same either way.
In this section
- Modes. Observe, assist and enforce, and the order to take them in.
- Writing a contract. The full shape, and what compiles.
- State reference. Every field a rule can read.
- The mandate. Ceilings, which sets load, and pointing the gate at your workflow.
- Escalations. The queue, and recording a decision on it.
- Reading the ledger. Receipts, filters and the chain.
- The dashboard. The browser surface, its API, and the pilot demo.
- Drafting from a policy. Turning a document into contracts.
- CLI reference. Every command and flag.