Skip to main content
Builtin policies cover secret handling, environment files, destructive shell commands, protected branches, cloud and infrastructure tools, package publishing, repeated calls, and end-of-task workflow checks.

Enable and verify a builtin policy

  1. Install the policy on a connected machine with the local CLI.
  2. Run a safe test action in the instrumented agent.
  3. Go to Observe → policy and filter by the policy name, machine environment, or decision.
  4. Open the linked session to confirm the matched tool input and returned reason.
List the policies available in your installed version:
Enable one policy for a project:
Enable several policies for selected harnesses:
Some policies accept parameters or are marked beta. Review the description, match scope, and default behavior before rollout. A policy that protects one workflow may block valid operations in another.

Browse the complete builtin catalog

Review all 40 current policies, their triggers, recommended baseline, and parameters.
Prefer project scope for repository-specific expectations and user scope for machine-wide safety requirements.