Skip to main content
Failproof AI keeps what a repository can commit — hook wiring, policy parameters, custom policies — apart from machine state such as credentials, installed packs, and the daemon.

Choose a scope

A scope decides where the hooks are wired, and which configuration file you write parameters and custom policy paths into:
  • User applies across projects on this machine.
  • Project belongs to the repository and can be committed.
  • Local overrides one project for one user and should remain gitignored.
Not every harness supports local scope; the CLI rejects a scope the selected harness cannot represent. Which pack policies are on is not scoped. The switch is recorded with the installed pack, so failproofai policies add <name> turns a policy on for the whole machine, whatever --scope says. Policy parameters use the first scope that defines parameters for that policy, in project → local → user order. Explicit custom policy paths use the first scope that defines them.

Configure policy parameters

Open the policy in the local dashboard, edit its supported parameters, and save in the selected scope. Run a matching and non-matching agent action, then inspect the decision in Observe → policy.

Parameters the Failproof AI policies accept

Each policy validates its own parameter types.
An allow pattern broadens what an agent may do. Test the exact tokenization and command variants on the target harness before deploying it across a fleet.

Understand the machine files

~/.failproofai contains separate files for separate trust boundaries: Use FAILPROOFAI_HOME to relocate the complete machine layout for a container or isolated test. Do not relocate individual state directories independently.
Never commit credentials.json. Commit project policy configuration and project convention policies only after reviewing them as enforcement code.