← Back to customers

How Cursor gives engineers and AI agents secure access with Formal

1,000s
Resources secured
10+
Technologies secured
~40M
Logs per week
~600K
Sessions per week

Cursor uses Formal to protect sensitive data, enforce least privilege, and give humans and agents the identity and access controls they need to do useful work. Formal secures SSH, PostgreSQL, Redis, ClickHouse, Kubernetes, and more at Cursor.

“With Formal, we can finally manage least privilege access across our entire infrastructure through a single control plane.”

— Tom Daniels, CISO @ Cursor

About Cursor

Cursor is an AI software development platform helping developers build, understand, and improve software. Trusted by more than half of the Fortune 500, it serves individual developers and enterprise engineering teams. Its tools bring AI into the editor, terminal, and cloud, so developers can move from targeted code changes to delegating entire tasks to autonomous agents. Cloud Agents work in their own environments to build, test, and demonstrate features for developers to review.

Alongside its products, Cursor develops its own coding models and conducts applied research to advance software development. Its focus spans the development lifecycle: helping teams write code, review changes, resolve issues, and turn ideas into working software while keeping developers in control of what they ship.

Enabling access without expanding risk

At Cursor, engineers increasingly work alongside agents that can write code, investigate incidents, and interact with internal systems. Making those agents useful requires access to the data and infrastructure behind the work.

That creates a particular challenge around Cursor’s model development environment. Training data and methodologies are critical assets, yet researchers need to move and use that data across systems for training, reinforcement learning, and evaluation.

Cursor needed to:

  • Give engineers and agents access appropriate to their work.
  • Enforce granular controls across different technologies.
  • Understand which identity was responsible for an action.
  • Reduce standing access while keeping essential workflows available.

Managing those requirements through separate access systems and custom proxies added complexity. The security team needed a common way to govern access wherever engineers and agents were working.

Why Cursor chose Formal

Formal gives Cursor control at the point where access happens. Its protocol-aware proxy understands the requests flowing to downstream systems, allowing the security team to inspect activity and enforce policies within the connection.

That combination of visibility and control makes least privilege practical across a diverse environment:

  • Granular enforcement. Policies can restrict access and apply conditions even where existing permissions are broader than the task requires.
  • Consistent controls for people and agents. A configurable policy engine governs both, including workflows where an agent acts on a person’s behalf.
  • Coverage across the stack. The same platform supports infrastructure, databases, and internal services, including SSH, PostgreSQL, Redis, ClickHouse, and Kubernetes.

Formal also preserves the identity context needed to evaluate access. The security team can connect an agent’s activity to the employee who authorized the work and check permissions at that level.

The result is a single place to express and enforce the conditions under which access is allowed, with visibility into the activity that follows.

On end-user identity propagation

“We’ve limited the amount of data that those cloud agents can access and we’re able to tie that back to the specific user who is using that cloud agent, which is a feature that I’m only aware of Formal having.”

— Roy Xu, Software Engineer, Security @ Cursor

Giving agents useful access to sensitive data

For Cursor’s internal Cloud Agent workflows, useful access means more than being able to read a repository. Employees want agents to work with the data and services needed to complete real tasks.

Formal makes that expansion possible with enforceable boundaries. Cursor combines isolated environments and tightly restricted outbound connections with scoped Formal policy enforcements on data. With Formal, the security team can determine what agents access while retaining visibility into their activity.

In ML environments, Formal sits between the environment an agent operates and the sensitive data it needs. That gives Cursor a place to inspect access and enforce policy as the agent works.

“We are able to provide a safe environment for the agents to actually get the job done.”

— Travis McPeak, Head of Security @ Cursor

Making identity the foundation of agent security

As agents take on more work, authorization needs to account for both the agent and the person delegating to it. A connection alone does not provide all the context needed to decide whether an action should be allowed.

For its internal Cloud Agent workflows, Cursor uses a specific Formal identity with limited access. End-user identity propagation connects the agent’s activity to the employee who initiated it, allowing permissions to be checked against the person behind the task.

That gives the security team two important points of control: the access granted to the Cloud Agent workflow and the permissions of the employee directing it. Agents can work within a defined scope while their actions remain attributable to the human who authorized the work.

As delegation becomes more autonomous, Cursor can build on a common identity and policy layer to govern access across the systems agents use.

Broader access with a smaller operational burden

Formal secures thousands of resources across 10+ technologies at Cursor, including SSH, PostgreSQL, Redis, ClickHouse, and Kubernetes. The deployment handles approximately 40 million logs and 600,000 sessions per week.

For Cursor, the value is the work that this foundation enables:

  • More capable agents. Internal Cloud Agents can access additional data under defined controls, expanding the tasks employees can delegate.
  • Accountable access. Agent activity remains connected to the person who initiated the work, with permissions evaluated in that context.
  • Less standing privilege. Engineers can receive temporary production access tied to an operational need.
  • A common control layer. Security teams can manage policies and audit activity across technologies with less overhead from separate access systems.

Looking ahead

As agents take on more autonomous work, Cursor wants to expand that foundation. The team plans to use Formal for broader visibility and guardrails around agent use across the company, extending controls across the environments and tools where that work happens.

The goal is to make more agent workflows possible with clear boundaries around identity, access, and data use. Formal gives Cursor a foundation to build on: agents can reach the systems they need, the security team can enforce the conditions of that access, and the people behind the work remain part of the authorization context.

Products Used

Policies End-user identity propagation Just-in-time access Logs