What SigmaShake does and why you need it
A five-minute read on what SigmaShake governs, how the CLI, Desktop, and dashboard fit together, and which tutorial to run next.
Let your AI agent install and set up SigmaShake
One pasteable prompt so your AI coding agent can install ssg, run ssg_onboard / ssg init --smart, install OS-correct Desktop, restart the client, and self-heal via ssg probe onboard.
Sign in
How to sign in to SigmaShake from the CLI or SigmaShake Desktop — every supported identity provider, headless flows, and how to confirm you're linked to the right account.
Subscribe and activate
How to start the $5/month SigmaShake subscription and activate the license on your machine — what unlocks, how to verify it, and how to manage or cancel later.
Let your agent write rules
How to safely let an AI agent author or edit .rules files itself — using ssg mode to pause enforcement for a bounded window instead of turning governance off for good.
Use the governed terminal
Run a real shell from the SigmaShake dashboard where every typed command is checked against your .rules before it executes — identical behavior on Linux, macOS, and Windows.
Configure the agent sandbox
Turn on each AI coding agent's own native sandboxing from one place — SSG toggles the provider's setting, verifies it, and shows you exactly what changed and how to undo it.
Allow the network domains your agent may reach
SSG denies unknown network egress by default. Learn how to review pending network requests and durably allow the domains your agent legitimately needs — from the CLI, the dashboard, or an interactive checklist.
Manage the host firewall
Check and manage your local firewall (ufw/nftables on Linux) from SSG — full status posture on every OS, rule management on Linux, with destructive changes routed through the governed terminal so you watch them happen.
Report a bug or get support
File a support ticket straight from the CLI with redacted diagnostics attached, or preview exactly what would be sent first with --dry-run — plus where to find a blocked call's audit trail before you file.