Tool approval
This Content policy pauses a selected tool before execution and creates an administrator approval request.require_approval requires exactly evaluateOn: ["pre_tool"]. The group name
is resolved to one exact directory binding when the policy is saved.
Result filtering
This Content policy removes objects classified as sensitive from a structured tool-result array.rows array.
onUnavailable: "block" prevents the original unfiltered result from
continuing if the expected structure is absent.
MCP control
This Content policy blocks one MCP tool for a selected group.Destination block
This Access policy blocks an AI destination at the endpoint route and provides a user-facing notification.acknowledgeBroadScope is required.
Account review
This Access policy records proven personal-account use for review without blocking the activity.Runtime quarantine
This Access policy blocks a selected runtime and authorizes quarantine after the block.process.id condition.
The selected enforcedBy integration must advertise support for
quarantineRuntime on local_runtime.
Rego match
This is thelogic.module for a Content policy that blocks a Shell tool call
when its structured command targets a production path:
appliesTo, evaluateOn: ["pre_tool"], and
action: "block". Rego supplies only the match result.
Block PostgreSQL deletes
This Resource Policy stops aDELETE command before it reaches one production
database and returns a useful message to the database client.
enforcement to
monitor. Keep enabled true so the policy participates in evaluation. The
effective operation remains allowed while Resource Activity records that the
policy would have blocked it.
Redact an HTTP request body
This Resource Policy replaces selected JSON values before the request reaches the destination. The body itself is never a condition input or retained evidence.Filter an HTTP response
Redact PostgreSQL result columns
dataTarget: "postgres_result", collectionPath: "$.rows", and a
removeWhere.path naming an exact column.
Require approval for a PostgreSQL command
Resource Rego match
Rego can select a request using Resource metadata while the typed policy configuration owns the transformation:action: "redact",
dataTarget: "http_request_body", and redaction. Rego cannot read the body,
emit transformation instructions, or create an approval grant.