Skip to main content
कस्टम policies आपके traces या audits से एक failure pattern को एक decision में बदल देते हैं जो agent के काम करते समय चलता है। एक policy एक action को allow कर सकता है, agent को guidance दे सकता है, या action को deny कर सकता है इससे पहले कि यह दूसरा incident का कारण बने। एक कस्टम policy का उपयोग करें जब behavior आपके tools, paths, commands, environments, या operating rules पर निर्भर करता हो। पहले Failproof AI policy pack को check करें ताकि आप एक existing control को recreate न करें।

कस्टम policy को author करें

  1. Admin → policy editor पर जाएं, New policy चुनें, और failure को describe करें जिसे आप prevent करना चाहते हैं।
  2. policy source को add करें, फिर editor में expected matches और safe non-matches को test करें। हर validation error को resolve करें।
  3. draft को save करें और Publish version को चुनकर एक immutable version बनाएं।
  4. Admin → enforcement पर जाएं, version को एक test machine में observe mode में deploy करें, और Observe → policy के अंतर्गत इसके decisions को verify करें इससे पहले कि आप इसे enforce करें। कस्टम policy को author और publish करने के लिए use की जाने वाली policy editor।

एक narrow rule के साथ शुरू करें

यह policy destructive Kubernetes commands को केवल तभी block करता है जब command production को target करता है। उस exact failure mode के बाहर सब कुछ allow() return करता है।
अच्छी policies उतनी narrow होती हैं कि एक sentence में explain की जा सकें। observable action को match करें—न कि वह intent जो आप उम्मीद करते हैं कि agent के पास हो—और allow() को return करें जैसे ही rule apply न हो।

एक decision चुनें

Agent के लिए reason लिखें जिसे recover करना होगा। Explain करें कि क्या detect किया गया और उसे इसके बजाय क्या करना चाहिए।
एक safety boundary के लिए instruct() का use न करें। Guidance delivery agent harness के आधार पर अलग-अलग होती है। deny() का use करें जब action को prevent किया जाना चाहिए।

Policy object

Tools को fn के अंदर filter करें। match.toolNames public custom-policy type का हिस्सा नहीं है।

Policy context

हर policy को एक PolicyContext मिलता है। हर optional value को genuinely optional मानें। Agent versions और event types सभी fields provide नहीं करते हैं।

Common tool inputs

Failproof AI common tools को supported harnesses के across normalize करता है ताकि एक policy आमतौर पर एक input shape use कर सके। Defensive coercion का use करें क्योंकि tool input values unknown के रूप में typed होती हैं:

Event को choose करें

Event availability और blocking behavior agent harness पर depend करते हैं। Mixed fleet के across एक event पर rely करने से पहले Agent harnesses को देखें।
SessionStart, SessionEnd, UserPromptSubmit, PreToolUse, PermissionRequest, PermissionDenied, PostToolUse, PostToolUseFailure, Notification, SubagentStart, SubagentStop, TaskCreated, TaskCompleted, Stop, StopFailure, TeammateIdle, InstructionsLoaded, ConfigChange, CwdChanged, FileChanged, WorktreeCreate, WorktreeRemove, PreCompact, PostCompact, Elicitation, ElicitationResult, UserPromptExpansion, PostToolBatch, और Setup।

Common policy patterns को author करें

Protected paths में writes को block करें

Non-blocking guidance दें

Session completion को gate करें

एक denied Stop event agent को retry करने के लिए कर सकता है। केवल एक ऐसी condition पर gate करें जिसे agent current environment में satisfy कर सकता है, और हर subprocess या network call को bound करें।

Policy files को load करें

Convention files

Convention files automatically load होती हैं:
  • Project और user policy directories दोनों को load किया जाता है।
  • Files प्रत्येक directory के अंदर alphabetically load होती हैं।
  • एक file को policies.js, policies.mjs, या policies.ts में end होना चाहिए।
  • एक file में multiple customPolicies.add() calls supported हैं।
  • Local modules से relative imports supported हैं।
  • Project policies को commit किया जा सकता है ताकि same rules repository को follow करें।

Explicit files

Explicit paths का use करें जब validation या configuration को entry file को directly name करना चाहिए:
Explicit files पहले load होती हैं, फिर project convention files और फिर user convention files। एक file जो दोनों paths के through discover होती है, एक बार load होती है।

Validate और test करें

Validation module को production loader के through execute करता है और confirm करता है कि यह कम से कम एक policy को register करता है।
Validation missing files, syntax errors, unresolved imports, top-level exceptions, और module-load timeouts को catch करता है। यह prove नहीं करता कि आपकी match logic सही है। कम से कम इन cases को test करें:
  • एक action जो match करना चाहिए और intended policy reason produce करना चाहिए।
  • एक nearby लेकिन safe action जो allow() return करना चाहिए।
  • Missing या malformed tool fields।
  • Alternate command syntax, paths, quoting, casing, और whitespace।
  • एक unavailable subprocess या network dependency।
Result को अपने custom policy के लिए Observe → policy के अंतर्गत attribute करें। एक blocked test sufficient नहीं है अगर एक different built-in policy ने decision बनाया है।

Runtime behavior

  • Built-in policies custom policies से पहले evaluate होती हैं।
  • पहला deny further policy evaluation को stop करता है।
  • Multiple instruct results को combine किया जा सकता है जब कोई भी policy event को deny नहीं करता है।
  • एक policy function के पास 10-second execution deadline होता है।
  • एक thrown exception या timeout को log किया जाता है और allow() के रूप में treat किया जाता है।
  • एक convention file जो load होने में fail होती है, को skip किया जाता है; अन्य custom files और built-in policies continue होती हैं।
  • Top-level module loading के पास भी 10-second deadline होता है।
  • Cloud observe mode policy को run करता है लेकिन एक non-allow decision को record करता है बिना इसे enforce किए।
Policy modules को deterministic और quick रखें। Top-level network calls या server startup से avoid करें। fn के अंदर work को bound करें, dependency failures को catch करें, और deliberately choose करें कि वह failure operation को allow या deny करना चाहिए।

API exports

TypeScript PolicyContext, PolicyResult, CustomHook, PolicyDecision, और PolicyFunction को export करता है।

कस्टम policies को deploy करें

एक version को publish करें, इसे observe mode में deploy करें, decisions को verify करें, और enforcement की ओर move करें।