Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion services/www/src/docs/content/config.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -190,7 +190,7 @@ statements that broader configuration can override.
"policies": [
{ "action": "provider.use", "resource": "*", "effect": "deny" },
{ "action": "provider.use", "resource": "anthropic", "effect": "allow" },
{ "action": "permission", "resource": "shell:git push *", "effect": "deny" },
{ "action": "tool.use", "resource": "shell:git push *", "effect": "deny" },
],
},
}
Expand Down
2 changes: 1 addition & 1 deletion services/www/src/docs/content/permissions.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -286,7 +286,7 @@ approvals run. It turns `allow` or `ask` into `deny` and never grants access.
```jsonc
{
"experimental": {
"policies": [{ "action": "permission", "resource": "shell:sudo *", "effect": "deny" }],
"policies": [{ "action": "tool.use", "resource": "shell:sudo *", "effect": "deny" }],
},
}
```
Expand Down
46 changes: 34 additions & 12 deletions services/www/src/docs/content/policies.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -31,11 +31,11 @@ valid credentials.

Each statement has three fields:

| Field | Values | Meaning |
| ---------- | ---------------------------- | ---------------------------------------------------- |
| `action` | `provider.use`, `permission` | The operation being controlled |
| `resource` | string or wildcard pattern | What the statement applies to; depends on the action |
| `effect` | `allow`, `deny` | The decision when this statement matches |
| Field | Values | Meaning |
| ---------- | ------------------------------------------- | ---------------------------------------------------- |
| `action` | `provider.use`, `tool.use`, `integration.use` | The operation being controlled |
| `resource` | string or wildcard pattern | What the statement applies to; depends on the action |
| `effect` | `allow`, `deny` | The decision when this statement matches |

Statements that fail validation are dropped with a warning in the server log and
the rest of the list still applies. Check the log after editing a `deny`.
Expand Down Expand Up @@ -108,16 +108,16 @@ lists. V1 files still load; see

## Permissions

`permission` statements hard-deny a [permission](/permissions) check. The resource is
`tool.use` statements hard-deny a [permission](/permissions) check. The resource is
`<action>:<value>`, matched against every resource the tool checks.

```jsonc
{
"experimental": {
"policies": [
{ "action": "permission", "resource": "shell:git push *", "effect": "deny" },
{ "action": "permission", "resource": "edit:*.env", "effect": "deny" },
{ "action": "permission", "resource": "webfetch:*", "effect": "deny" },
{ "action": "tool.use", "resource": "shell:git push *", "effect": "deny" },
{ "action": "tool.use", "resource": "edit:*.env", "effect": "deny" },
{ "action": "tool.use", "resource": "webfetch:*", "effect": "deny" },
],
},
}
Expand All @@ -136,22 +136,44 @@ applies after agent rules and saved approvals, so it overrides an `ask` and an
| `github_delete_repository:*` | One MCP tool |
| `*` | Everything not already denied |

A `permission` statement with `allow` never grants access. It only lifts an earlier
A `tool.use` statement with `allow` never grants access. It only lifts an earlier
broader `deny`, after which the agent's own rules decide.

```jsonc
{
"experimental": {
"policies": [
{ "action": "permission", "resource": "shell:*", "effect": "deny" },
{ "action": "permission", "resource": "shell:git status *", "effect": "allow" },
{ "action": "tool.use", "resource": "shell:*", "effect": "deny" },
{ "action": "tool.use", "resource": "shell:git status *", "effect": "allow" },
],
},
}
```

`git status` falls back to the agent's `shell` rule; every other command is blocked.

## Integrations

Use `integration.use` to remove an MCP server or skill from its catalog. Resources
are `mcp:<server-name>` for [MCP servers](/mcp-servers) and `skill:<id>` for [skills](/skills),
including the skill's namespace when present.

```jsonc
{
"experimental": {
"policies": [
{ "action": "integration.use", "resource": "mcp:github", "effect": "deny" },
{ "action": "integration.use", "resource": "skill:*", "effect": "deny" },
{ "action": "integration.use", "resource": "skill:team:review", "effect": "allow" },
],
},
}
```

This removes the `github` MCP server and its tools, and hides every skill except
`team:review`. The last matching statement wins; an `allow` lifts an earlier policy
deny but does not grant tool permissions.

## Precedence

Ordinary settings let the nearest configuration win. Policies reverse that: statements
Expand Down
Loading