What can Bursar do?
Once your agent is registered with Bursar (see Installing the MCP client) and has its own certificate identity (see Installing your first agent identity), it can do a lot more than just chat. This article is a tour of what that actually means in practice, organized around what your agent can do — not the technical mechanics of how it does it.
Look at a codebase and tell you how exposed it is
Point your agent at a project and it can scan it for security risk — what's there, what's talking to the outside world, and what needs attention before it ships. This works immediately, with no Blacksands account required, so it's a reasonable first thing to try.
Spot what a project is actually built on and handling
Beyond a general risk scan, your agent can identify the frameworks a project is built on, flag where personal or sensitive data (PII) shows up in the code, notice which outside services and APIs it talks to, and identify the databases or data stores it depends on. Together, these give you a much clearer picture of what a piece of software actually touches — useful whether you're onboarding a legacy app or reviewing something new before it goes live.
Bring an organization or application into Blacksands
When you're ready to move from "just scanning" to actually protecting something, your agent can walk you (or itself) through onboarding — setting up your organization and registering an application so it's known to Blacksands and eligible for the protections described below.
Manage certificates
Certificate identities are how Blacksands recognizes agents, devices, and services instead of relying on static credentials (see Understanding agent identities and scoped access). Your agent can issue new certificates, rotate ones that are aging out, and revoke ones that should no longer be trusted, all without you touching a certificate file directly.
Check and report on compliance posture
Your agent can pull together a compliance report and check your posture against the relevant controls, giving you a status snapshot you can share internally or with an auditor rather than compiling one by hand.
Manage Receivers — the edge proxies that guard your services
A Receiver is the edge proxy that sits in front of a protected service. Your agent can help bring a new Receiver online, check whether an existing one is healthy, and manage which services it's protecting — the operational side of keeping your protected surface running.
Hit the emergency brake
If something goes seriously wrong — a compromised agent, a service behaving unexpectedly — your agent can trigger an emergency lockdown that cuts off access immediately, and lift it again once the situation is resolved. This is the "break glass" control for when you need to stop everything now and sort out the details after.
Install an agent on a remote machine
Rather than manually connecting to every machine an agent needs to run on, your agent can install itself (or another agent) remotely, extending Blacksands protection to new hosts without a separate manual setup pass on each one.
Ask "who am I?"
At any point, your agent can check its own identity — which certificate it's presenting, which organization it belongs to, and what role it has. This is a useful first troubleshooting step any time something isn't behaving the way you expect: confirm the agent knows who it is before digging further into what it's allowed to do (see Understanding agent identities and scoped access) or checking the access ledger for what it's actually done.
Going deeper
This article deliberately stays at the "what," not the "how." For the full technical reference of every capability, tool by tool, see the Bursar FAQ and the full 55-tool training guide. For the mechanics of how an admin issues a setup token and a non-coder teammate redeems it, see Getting started in the Bursar FAQ.
For related reading in this category, see Installing the MCP client, Understanding agent identities and scoped access, and Reading the access ledger.
