Skip to main content
The definitions below use the same schemas as the Forge Console, API, and Terraform provider. Replace example identifiers with values resolved from your own Forge organization. Access, Content, and Resource are peer authoring families over the same policy engine. Examples differ in scope, fields, and capability-gated actions, not in their revision, exception, policy-as-code, backtest, or ownership model.

Tool approval

This Content policy pauses a selected tool before execution and creates an administrator approval request.
require_approval requires exactly evaluateOn: ["pre_tool"]. The group name is resolved to one exact directory binding when the policy is saved.

Result filtering

This Content policy removes objects classified as sensitive from a structured tool-result array.
The policy acts only on tool results whose root contains a rows array. onUnavailable: "block" prevents the original unfiltered result from continuing if the expected structure is absent.

MCP control

This Content policy blocks one MCP tool for a selected group.
Use the stable Registry IDs supplied by Forge. A tool condition must identify exactly one parent MCP server.

Destination block

This Access policy blocks an AI destination at the endpoint route and provides a user-facing notification.
Because the scope is organization-wide and the action is disruptive, acknowledgeBroadScope is required.

Account review

This Access policy records proven personal-account use for review without blocking the activity.
The second condition prevents the policy from treating hinted or inferred account metadata as proven.

Runtime quarantine

This Access policy blocks a selected runtime and authorizes quarantine after the block.
Forge derives the remediation target from the positive process.id condition. The selected enforcedBy integration must advertise support for quarantineRuntime on local_runtime.

Rego match

This is the logic.module for a Content policy that blocks a Shell tool call when its structured command targets a production path:
The policy object still supplies appliesTo, evaluateOn: ["pre_tool"], and action: "block". Rego supplies only the match result.

Block PostgreSQL deletes

This Resource Policy stops a DELETE command before it reaches one production database and returns a useful message to the database client.
To observe the same matches before enforcement, set enforcement to monitor. Keep enabled true so the policy participates in evaluation. The effective operation remains allowed while Resource Activity records that the policy would have blocked it.

Redact an HTTP request body

This Resource Policy replaces selected JSON values before the request reaches the destination. The body itself is never a condition input or retained evidence.
The request must contain one complete, uncompressed JSON value no larger than 32 KiB. If an enforcing policy matches and Forge cannot safely transform the body, the request is blocked before forwarding.

Filter an HTTP response

Redact PostgreSQL result columns

PostgreSQL filtering uses the same filter object with dataTarget: "postgres_result", collectionPath: "$.rows", and a removeWhere.path naming an exact column.

Require approval for a PostgreSQL command

The first command is rejected with an approval reference. Approval creates a ten-minute, one-use grant; the same caller must retry the identical command.

Resource Rego match

Rego can select a request using Resource metadata while the typed policy configuration owns the transformation:
The surrounding Resource Policy sets action: "redact", dataTarget: "http_request_body", and redaction. Rego cannot read the body, emit transformation instructions, or create an approval grant.