The installed package is the source of truth for policy availability. Run failproofai policies after every upgrade because catalog entries and behavior can change with the package version.
Recommended baseline
The guided setup’s recommended selection currently enables secret sanitizers, environment protections, self-protection, catastrophic-command guards, and protected-branch safety:
Recommended is deliberately narrower than Everything. Infrastructure and workflow policies can interrupt valid work and should be enabled for the repositories and machines that need them.
Secrets and environment
Dangerous commands and infrastructure
Git and database safety
Packages, system behavior, and agent loops
End-of-task workflow
These policies require a harness that emits a compatible Stop event.
Parameter reference
Configure parameters under the selected scope’s policyParams object. Types are validated by each policy.
An allow pattern broadens what an agent may do. Test the exact tokenization and command variants on the target harness before deploying it across a fleet.