Talk this topic through with an AI

You get an answer from the documentation and the page it comes from.

Installation & operation

Onboarding

Six steps for admins and developers, from the install key to feedback.

~5 min read · Installation & operation

1. Prepare the console

PlanConsole
Enterprisehttps://<company>.poison0.com or your own domain
Solo Dev, Prohttps://console.poisonzero.com
  1. Invite more admins: Settings → Access & Security → People → enter the email → Invite. The link is valid for 7 days.
  2. Create an install key: Devices → Roll out many devices with a key → Choose variant: Cloud → Generate key. The key is shown only once.
  3. Pass the key to developers or IT. It is valid for 30 days and for as many devices as your plan allows (Enterprise: unlimited).

2. Install

Option A or B. Both set up /pz and the status line in Claude Code.

Check after installing: restart Claude Code. The status line shows 🛡 PoisonZero 🟢.

2A. Developer installs it

bashTerminal
curl -fsSL https://poisonzero.com/install.sh | sudo PZ_ENROLL_CODE=<install-key> PZ_SETUP_AGENTS=claude PZ_SETUP_STATUSLINE=1 sh
powershellPowerShell as administrator
$env:PZ_ENROLL_CODE='<install-key>'; $env:PZ_SETUP_AGENTS='claude'; $env:PZ_SETUP_STATUSLINE='1'; irm https://poisonzero.com/install.ps1 | iex
Servers without a desktop (e.g. over SSH): also set PZ_HEADLESS=strict. Unclear changes are then rolled back immediately instead of asking in a dialog. Without it, PoisonZero detects this itself.

2B. IT deploys via Jamf, Intune or Ansible

Step 1: install (as root or SYSTEM)

bashroot
PZ_ENROLL_CODE=<install-key> sh -c "$(curl -fsSL https://poisonzero.com/install.sh)"
powershellSYSTEM
$env:PZ_ENROLL_CODE='<install-key>'; irm https://poisonzero.com/install.ps1 | iex

Step 2: set up Claude Code (as the signed-in user)

bashUser
poisonzero setup-claude
poisonzero setup-claude --statusline-only
powershellUser
& "$env:ProgramFiles\PoisonZero\poisonzero.exe" setup-claude
& "$env:ProgramFiles\PoisonZero\poisonzero.exe" setup-claude --statusline-only
bashroot, in the signed-in user's account
u=$(stat -f%Su /dev/console)
sudo -u "$u" -H env -u SUDO_USER /usr/local/bin/poisonzero setup-claude
sudo -u "$u" -H env -u SUDO_USER /usr/local/bin/poisonzero setup-claude --statusline-only
ToolSetting
Intune“Run this script using the logged on credentials: Yes”. The full path is needed because PATH does not include the program folder.
JamfRuns as root; the Jamf tab runs step 2 in the account of the signed-in user.

2C. Device name at install time (optional)

Set one of these variables next to PZ_ENROLL_CODE. The first one set, in this order, applies:

VariableEffect
PZ_DEVICE_NAME="Platform / Laptop 07"The name is taken as is
PZ_DEVICE_NAMES_CSV=<file or https URL>CSV with the header hostname,name. The installer looks up its own hostname and takes the name. Only the name is sent, never the hostname
PZ_DEVICE_NAME_FROM_HOSTNAME=1The hostname becomes the device name. Not recommended
textpz-names.csv
hostname,name
mbp-0231,Platform / Laptop 07
The device name is chosen by the administrator. PoisonZero does not want personal data. Rules: 1 to 60 characters, no control characters; an invalid name is ignored and the device is still enrolled. On an upgrade the variables are ignored. From version 1.16.45.

3. Set up

  1. Name devices that have no name: Devices → on the device Rename device → enter the Display name of the device, for example “Platform / Laptop 07”.
  2. Separate teams (optional): create one install key per team, each with its own Profile (optional). Manage profiles: Settings → Protection & Devices → Profiles.

4. Use

WhereInputResult
Claude Code/pzProtection stats for this month
Claude CodeStatus line🟢 protection running; 🟡 service running but reports a problem; 🔴 service not running
Command linepoisonzero statsProtection stats
Command linesudo poisonzero statusAll decisions, open quarantine
Command linesudo poisonzero quarantine listHeld-back changes; show, restore, discard <id>
Command linepoisonzero doctorSelf-test
Command linesudo poisonzero egressWhat left the machine (Linux: also without sudo)
Windows: no sudo; use PowerShell as administrator and the full path & "$env:ProgramFiles\PoisonZero\poisonzero.exe".
Update via/pz in Claude Code
install.sh, install.ps1Existing /pz files of the installing user are renewed automatically
Homebrew, Scoop, .deb/.rpm, automatic updateEach user runs poisonzero setup-claude once

5. View telemetry

ConsoleContent
DevicesState and incidents per device
AnalyticsBlocked changes by type and day; filter by device, agent, operating system, 7/30/90 days
AuditEvery incident with its redacted attack content
Never transmitted: full file contents (only redacted changes), files outside the protected paths, process and system information.

6. Give feedback

WhereInput
Claude Code/pz feedback <text>
Command linepoisonzero feedback "<text>" (no sudo)
ItemRule
LengthAt most 2000 characters
RedactionLocally before sending: secrets, email addresses, IBANs, card numbers, IP addresses, phone numbers, key and token assignments, and the user name in home paths (/Users/<name>, /home/<name>, C:\Users\<name>). The command shows the text after redaction
SendingWith the next check-in. The device sends only the text, version and platform; on arrival PoisonZero stores the device's current name with it
RecipientOnly the PoisonZero team sees the text, not your own admins
ReplyIf the team replies, the account owner is told the date and device of the feedback, not its text
Private modeBlocked; use the contact form on poisonzero.com instead

Every installer variable and path: installing PoisonZero. What the console shows per incident: incidents and audit. How updates arrive: updates and lifecycle.