How do you implement AI access control for Claude Code, Codex CLI, and Cursor?

Coding agents like Claude Code, Codex CLI, and Cursor execute on developer machines with broad local privileges. AI access control for these agents needs to happen where they actually run.