Bluebear for Cursor

Roll out Cursor with visibility and runtime control. Govern what Cursor’s agent runs, writes, and installs on developer machines, track drift in your team’s security settings, and see who is using which models against which repositories. Review the findings together in Bluebear, next to the ones from Claude Code and your other agents.

Available now for Cursor Enterprise teams. Request access · How to enable it

Bring Cursor activity into your security workflow

Cursor’s agent runs shell commands, edits files across the repository, calls MCP servers, and with Cloud Agents does all of that on infrastructure you do not manage. Cursor’s audit log records administrative events and its usage data records requests; by design neither contains what the agent did. The team settings that matter drift after they are set.

Bluebear connects in two places. Through the Admin API it reads your team’s members, usage, and audit log, and checks your settings against a secure baseline. Through the endpoint handler on the developer machine, and through Cursor’s own team hooks, it sees what the agent actually runs and applies your policies before it does, with an approval in Slack or the terminal when a human should decide. Usage data is retrospective evidence. The handler is enforcement.

What a finding looks like

From Bluebear’s technical risk brief, Ten ways AI agents cross runtime boundaries.

A developer asks the agent to compare Terraform with production, then says “let’s fix it.” The agent finds a production network interface missing from Terraform and reads “fix it” as permission to delete the live resource, without confirming which side was authoritative.

Bluebear identifies the drift from reconcile to delete, holds the AWS command, and routes it to human review. The deletion is denied before it runs. Cloud IAM would have allowed it; it does not know that the agent changed the task from compare to delete.

What you get

  • Visibility. Team-wide Cursor usage by user, model, request type, and repository, including Cloud Agents and the CLI, in the same console as your other agents.
  • Runtime control. Policy enforcement, approvals, and sandboxing for Cursor’s agent on the developer machine, and inside Cursor’s agent loop through team hooks.
  • Posture. Cursor Enterprise settings checked against a secure baseline, with an incident for every drift and automatic resolution when it is fixed.
  • Data protection. Secrets, PII, and source code leaving the machine through agent tool calls, held before they go.

Set up the integration

You need a Cursor Enterprise team, an admin role on it, and an administrator role in Bluebear.

  1. In the Cursor dashboard, create an Admin API key with read-only scopes.
  2. In the Bluebear console, open Settings → Integrations → Cursor, paste the key, and click Test Connection.

Findings start within the hour. The integration is read-only against Cursor, and Bluebear keeps request metadata, not prompts or code. The endpoint handler and the Cursor team hook are set up from the Bluebear console.

When you have guardrails on a bridge, you can run.

Cursor tells you that a request happened. Bluebear tells you what the agent did with it, holds the actions that need a human, and alerts when the team’s settings drift. Request access and we will set your organization up.

Ready to start securing your AI agents?

Safe to imagine