Enterprise AI adoption stacks five layers. Blekline operates at Layer 4 — Non-Human Identity & Runtime Enforcement (MCP ingress and sidecar). Layer 1 sandbox providers (Daytona, Modal, Vercel Sandbox, Cloudflare, E2B) run isolated agent code.
The five layers
| Layer | Name | Role | Examples |
|---|---|---|---|
| L5 | Agent consumer | Autonomous and assistive agents that plan, call tools, write code | See L5 table below |
L5 agent clients (OSS config paths)
| Client | Capability | OSS path | Docs |
|---|---|---|---|
| CLI / SDK | verified | cli/ | Quick start |
| Cursor | verified | .cursor/mcp.json.example | Cursor |
| Claude Code | verified | .claude/settings.json.example | Claude Code |
| Claude Desktop | verified | config/claude_desktop_config.json.example | Claude Desktop |
| Codex | verified | .codex/config.toml.example | Codex |
| GitHub Copilot | verified | .vscode/mcp.json.example | Copilot |
| Continue | verified | .vscode/continue.config.json.example | Continue |
| OpenHands | pattern | — (app docs) | OpenHands |
| Sourcegraph Cody | pattern | — (app docs) | Cody |
| Claude connector | cloud-only | remote MCP on app.blekline.com | Claude connector |
| L4 | Runtime enforcement & NHIM | Mask, classify risk, enforce MCP tool policy, audit | Blekline — security plane for machine identities |
| L3 | Engineering | Training, eval, testing, quality for agent systems | LangSmith, Guardrails, Braintrust |
| L2 | Intelligence | Frameworks, retrieval, coding models | LangChain, LlamaIndex, Azure OpenAI, OpenRouter |
| L1 | Infrastructure | Sandboxes, model APIs, cloud compute | Sandbox providers — Daytona, Modal, E2B, Cloudflare, Vercel |
Request flow (Blekline + L1 sandbox)
flowchart TB
subgraph L5["L5 — Agent consumer"]
A[Cursor / Claude / Codex]
end
subgraph L4["L4 — Blekline governance"]
MS[mcp-server]
MP[mcp-proxy]
CP[mask · enforce · audit]
end
subgraph L1a["L1 — Sandbox MCP"]
S[L1 runtime MCP]
M[Model APIs]
end
A --> MS
A --> MP
MP --> MS
MS --> CP
MP --> CP
CP --> M
MP --> S
Why Layer 4 matters
Teams ship L5 agents before L4 governance is in place. One tool_call can leak an API key, run an unapproved shell command, or send PII to a model — while the agent UI still looks healthy.
Blekline sits at the MCP boundary: every prompt and tool invocation can be masked, evaluated, and audited before traffic reaches L1 runtimes or model APIs.
See Why ingress governance for the problem framing and Architecture for component wiring.
Open core vs cloud
| Capability | OSS (blekline-oss) | Cloud (app.blekline.com) |
|---|---|---|
| MCP server / proxy | Yes | Yes |
| Local secret + tool enforce | Yes (@blekline/contracts) | Yes |
| Azure authoritative PII mask | — | Yes |
| Fleet policy (SSE) | — | Yes |
| Investigations / billing | — | Yes |
Next steps: Quick start · Agent clients · Model providers · Sandbox providers · MCP Cursor setup · Open workspace