lando

The control plane for AI-native developer machines

Your coding agents understand the code. Lando understands the machine.

Claude Code and Codex get the minimum verified capability on a managed Mac, run as the developer, with a signed receipt. No ticket. No standing admin rights.

POLICY BOUNDARY AGENTS
Herding, not guarding

How it works

The model proposes. Policy decides. A root broker executes, as you.

agent

Detect

A hook sees the failing command.

lando

Plan

The minimum fix, from a fixed library.

policy

Decide

Deterministic. Signs a grant.

root broker

Execute

Verifies the grant. Runs as you.

lando

Verify

Fresh inspection. Signed receipt.

$ npm test
The engine "node" is incompatible with this module. Expected 20.x
lando: 4 blockers · plan · policy ALLOW ×4
✓ select_runtime_version node 20.20.2 via nvm, as dev
✓ start_compose_service postgres via OrbStack, as dev
✓ write_env_from_template DATABASE_URL filled · STRIPE_KEY → 1Password reference
✓ trust_internal_ca internal root CA, in the system broker as root
environment READY · 4 receipts signed · 0 values on disk

The proof object

Every change wears a tag.

A grant before, a receipt after, both signed by your control plane. The same seal shows in the terminal, the dashboard and the audit export.

LANDO
Execution receipt signed by brokerd
operation
select_runtime_version
result
success
developer
github:leipan
device
dev_f979…0508
policy
2026.10.08-001
executed
worker · dev (uid 502)
why · developer has "write" on acme/node-demo; operation classed "safe"; arguments satisfy allowlists
grant · safe review · admin verified · ready denied

Developers

Open the repo, start the agent, get to green.

Security

No root shell for agents. Policy diffed, simulated, promoted by two people.

IT

Keep Jamf or Kandji. A signed package, a launch daemon, managed settings.

Where enforcement comes from

The honest version, because your CISO will ask.

The signed grant is the boundary

Anything can talk to the broker. It only does what your control plane signed, for this device and this developer.

Root buys tamper resistance

Operations run in a worker as the developer. Root means the daemon cannot be stopped or re-pointed without admin rights.

Secrets never sit on the laptop

Values arrive per grant. 1Password items stay references, resolved at run time under the developer's own identity.

Two fleets, two claims

Without admin rights, Lando is the only path to a working environment. With them, it is the paved road plus the audit trail.

How enforcement works Threat model, operation reference and admin FAQ: pilot teams

Design partners

Six-week pilots on locked-down Mac fleets.

Observe-only first, then remediation on a canary cohort. Three to five teams.

Pilot intake opens shortly.

WORKING DOG · GETLANDO.DEV · NO ROOT FOR AGENTS ·