Shield KYA gives developers and platform teams control over AI agents that can change real systems. Install with npm i -g @shield-agent/kya@latest && kya start and the CLI auto-wires Cursor, Claude Code, Grok, Kimi, and 15+ other hosts through a local MCP gate. Every tool call is evaluated against your policy: Allow, hold for Review, or Deny. All decisions stream to a live local report with session rollups, reason codes, sandbox inventory, wired-host status, cost showback, and a continuous Agent Trust Baseline gap report. KYA is free and MIT-licensed for individuals. The same agent identity and policy engine work on the IDE plane and the runtime plane, so a policy you test locally runs unchanged in production. Teams can upgrade to the hosted desk at shield-agent.com for SSO, SCIM, approvals, and multi-tenant governance. Audit trail and traceability for AI agents. Gate, record, and certify every tool call.