allowlets the action continue.instructgives the agent corrective guidance.denyblocks the action with a reason.
Use the three policy surfaces
- Dashboard
- CLI
- Go to Observe → policy to filter and inspect policy decisions from sessions.
- Go to Admin → policy editor to compose, validate, publish, disable, or inspect immutable versions.
- Go to Admin → enforcement to assign versions and effects to machines.



- Analyze decisions in sessions, dashboards, and audits.
- Author versions with builtin rules, code, or the policy editor.
- Deploy and enforce versions across selected machines.
Use a builtin policy
Enable a reviewed rule for common secret, shell, Git, cloud, and workflow risks.
Write a custom policy
Express a workflow-specific decision in JavaScript or TypeScript.

