Onboarding
Six steps for admins and developers, from the install key to feedback.
1. Prepare the console
| Plan | Console |
|---|---|
| Enterprise | https://<company>.poison0.com or your own domain |
| Solo Dev, Pro | https://console.poisonzero.com |
- Invite more admins: Settings → Access & Security → People → enter the email → Invite. The link is valid for 7 days.
- Create an install key: Devices → Roll out many devices with a key → Choose variant: Cloud → Generate key. The key is shown only once.
- Pass the key to developers or IT. It is valid for 30 days and for as many devices as your plan allows (Enterprise: unlimited).
2. Install
Option A or B. Both set up /pz and the status line in Claude Code.
Check after installing: restart Claude Code. The status line shows 🛡 PoisonZero 🟢.
2A. Developer installs it
bashTerminal
curl -fsSL https://poisonzero.com/install.sh | sudo PZ_ENROLL_CODE=<install-key> PZ_SETUP_AGENTS=claude PZ_SETUP_STATUSLINE=1 sh
powershellPowerShell as administrator
$env:PZ_ENROLL_CODE='<install-key>'; $env:PZ_SETUP_AGENTS='claude'; $env:PZ_SETUP_STATUSLINE='1'; irm https://poisonzero.com/install.ps1 | iex
Servers without a desktop (e.g. over SSH): also set
PZ_HEADLESS=strict. Unclear changes are then rolled back immediately instead of asking in a dialog. Without it, PoisonZero detects this itself.2B. IT deploys via Jamf, Intune or Ansible
Step 1: install (as root or SYSTEM)
bashroot
PZ_ENROLL_CODE=<install-key> sh -c "$(curl -fsSL https://poisonzero.com/install.sh)"
powershellSYSTEM
$env:PZ_ENROLL_CODE='<install-key>'; irm https://poisonzero.com/install.ps1 | iex
Step 2: set up Claude Code (as the signed-in user)
bashUser
poisonzero setup-claude poisonzero setup-claude --statusline-only
powershellUser
& "$env:ProgramFiles\PoisonZero\poisonzero.exe" setup-claude & "$env:ProgramFiles\PoisonZero\poisonzero.exe" setup-claude --statusline-only
bashroot, in the signed-in user's account
u=$(stat -f%Su /dev/console) sudo -u "$u" -H env -u SUDO_USER /usr/local/bin/poisonzero setup-claude sudo -u "$u" -H env -u SUDO_USER /usr/local/bin/poisonzero setup-claude --statusline-only
| Tool | Setting |
|---|---|
| Intune | “Run this script using the logged on credentials: Yes”. The full path is needed because PATH does not include the program folder. |
| Jamf | Runs as root; the Jamf tab runs step 2 in the account of the signed-in user. |
2C. Device name at install time (optional)
Set one of these variables next to PZ_ENROLL_CODE. The first one set, in this order, applies:
| Variable | Effect |
|---|---|
PZ_DEVICE_NAME="Platform / Laptop 07" | The name is taken as is |
PZ_DEVICE_NAMES_CSV=<file or https URL> | CSV with the header hostname,name. The installer looks up its own hostname and takes the name. Only the name is sent, never the hostname |
PZ_DEVICE_NAME_FROM_HOSTNAME=1 | The hostname becomes the device name. Not recommended |
textpz-names.csv
hostname,name mbp-0231,Platform / Laptop 07
The device name is chosen by the administrator. PoisonZero does not want personal data. Rules: 1 to 60 characters, no control characters; an invalid name is ignored and the device is still enrolled. On an upgrade the variables are ignored. From version 1.16.45.
3. Set up
- Name devices that have no name: Devices → on the device Rename device → enter the Display name of the device, for example “Platform / Laptop 07”.
- Separate teams (optional): create one install key per team, each with its own Profile (optional). Manage profiles: Settings → Protection & Devices → Profiles.
4. Use
| Where | Input | Result |
|---|---|---|
| Claude Code | /pz | Protection stats for this month |
| Claude Code | Status line | 🟢 protection running; 🟡 service running but reports a problem; 🔴 service not running |
| Command line | poisonzero stats | Protection stats |
| Command line | sudo poisonzero status | All decisions, open quarantine |
| Command line | sudo poisonzero quarantine list | Held-back changes; show, restore, discard <id> |
| Command line | poisonzero doctor | Self-test |
| Command line | sudo poisonzero egress | What left the machine (Linux: also without sudo) |
Windows: no
sudo; use PowerShell as administrator and the full path & "$env:ProgramFiles\PoisonZero\poisonzero.exe".| Update via | /pz in Claude Code |
|---|---|
install.sh, install.ps1 | Existing /pz files of the installing user are renewed automatically |
Homebrew, Scoop, .deb/.rpm, automatic update | Each user runs poisonzero setup-claude once |
5. View telemetry
| Console | Content |
|---|---|
| Devices | State and incidents per device |
| Analytics | Blocked changes by type and day; filter by device, agent, operating system, 7/30/90 days |
| Audit | Every incident with its redacted attack content |
Never transmitted: full file contents (only redacted changes), files outside the protected paths, process and system information.
6. Give feedback
| Where | Input |
|---|---|
| Claude Code | /pz feedback <text> |
| Command line | poisonzero feedback "<text>" (no sudo) |
| Item | Rule |
|---|---|
| Length | At most 2000 characters |
| Redaction | Locally before sending: secrets, email addresses, IBANs, card numbers, IP addresses, phone numbers, key and token assignments, and the user name in home paths (/Users/<name>, /home/<name>, C:\Users\<name>). The command shows the text after redaction |
| Sending | With the next check-in. The device sends only the text, version and platform; on arrival PoisonZero stores the device's current name with it |
| Recipient | Only the PoisonZero team sees the text, not your own admins |
| Reply | If the team replies, the account owner is told the date and device of the feedback, not its text |
| Private mode | Blocked; use the contact form on poisonzero.com instead |
Read next
Every installer variable and path: installing PoisonZero. What the console shows per incident: incidents and audit. How updates arrive: updates and lifecycle.