Bay is built for one problem: AI agents running on employee and developer devices with the user's access to files, credentials, shells and cloud CLIs. Its public material describes three layers it calls See it, Know it and Rule it: an inventory of every AI agent, MCP server, tool, credential exposure and risky setting across the fleet; activity monitoring that records who triggered each action and whether a person was involved; and enforcement that returns Allow, Ask or Deny for each action.
The enforcement detail is specific. Bay states that on supported agent surfaces it evaluates prompts, pre-tool calls and post-tool responses locally, in under 4ms, using the session context: identity, prior actions and data accessed. Capability rules cover shell and code execution, process spawning, package installation, cloud CLIs, containers, Kubernetes, browser automation and system changes. For Claude Code, Codex and Claude Desktop, administrators can lock permission rules, restrict MCP servers and constrain plugin sources. New rules can run in Simulation Mode first.
Deployment is the other reason. Bay says it deploys through your existing EDR or MDM as an ephemeral binary that runs and exits, with no new agent on the device. That positions it alongside your EDR rather than against it: the EDR keeps doing process and malware protection, and Bay adds the agent-level decisions the EDR does not make.
Where Bay loses
- Maturity and transparency (3 out of 10, lowest in this guide). Bay's public site has two blog posts, no documentation portal and no published pricing. Ask for architecture documents and references during evaluation.
- Coverage beyond the endpoint (4 out of 10, also lowest in this guide). Bay does not describe coverage for SaaS agents, cloud-hosted AI apps or red teaming. If those matter, Noma Security, Zenity or Onyx cover more ground.
- Vendor-stated outcomes such as "under 5 minutes to full deployment" and "under 1% false positive rate" are Bay's own figures and have not been verified by us.
Read the full Bay review
Source: bay.io · bay.io/blog/ghostjacking-ai-agent-attack · Reviewed Sep 2026