
The Policies page, marked Early access.
How a policy is evaluated
A policy has four parts. The builder walks through them in this order.- A deny always wins. When policies overlap, a matching deny refuses the call whatever any allow says. Put exceptions inside the deny rule, under Exempt from this rule, rather than in a separate allow.
- Policies narrow access. They never grant a tool the member could not already reach. Connector Profile scoping and account access still apply.
- Policies follow the member. A call is governed when it carries the identity of an organization member, which is the case for sessions created when a member connects an AI platform. A call made with a project API key alone carries no member identity, so member policies do not apply to it. Keep Connector Profile scoping in place for that traffic.
Capabilities
Three capabilities, each scoped on its own terms.Create a policy
Open Policies
Contractors cannot delete records.Pick the mode and status
Choose who it applies to
Choose what it does
Set the capability and its targets
- Everything covers every tool in the project.
- A connector category or A connector covers every tool on the connectors you pick, including connectors added later in that category.
- An account covers the tools of specific Linked Accounts. Search accounts by name or owner.
- Specific tools lets you pick a connector, then the tools on it by name.
*delete*. A capability takes either specific tools or a pattern, not both. Choose Add capability to cover another capability, or the same one over a second selection; the rule applies where any of them matches.Add exemptions
Review and create
*delete* on Workday, except Finance (Group). Under it, Fields is the form you have been filling in; switch to Cedar or JSON to read the rule the engine will evaluate. Then choose Create policy.If you used the assistant, the button reads Accept changes and create until every change it made has been reviewed. See Build a policy with the assistant.
A deny rule on the Create policy panel, with Monitor only and Active selected and Fields / Cedar / JSON above the form.
Build a policy with the assistant
Policy chat sits beside the form in the create and edit panels. Describe the rule you want in your own words and it fills the form in for you, so you do not have to know which capability or target expresses what you mean. It is answered by Claude Haiku 4.5, named under the chat header. The assistant fills in the form and never saves:- Every change lands on the field it belongs to, marked AI, with the previous value shown underneath as Was ….
- Each marked field carries its own Accept and Revert, and a bar at the top of the column carries Accept all and Revert all.
- Until every marked change is accepted or reverted, the panel’s button reads Accept changes and create (or Accept changes and save when editing) and nothing is written.

Policy chat beside the form. The assistant looked up the Contractors group, proposed a deny rule, and left three changes marked for review.
What it can look up
The assistant can look things up in the project while it drafts, and the transcript shows each lookup as it runs:*delete* pattern rather than making you pick the tools by hand.
It also flags what a rule will miss. A pattern matching delete does not catch a connector that names the same operation remove or archive, and the assistant says so rather than leaving you to find out from a call that went through.
Starting from a logged call
A rule usually starts with a call that should not have happened. On a log record, Use in policy opens the Policies page with that call attached, and you can then tell the assistant what to do about it in words: this call should not have been allowed, or this person should not have been allowed to make it. It opens the list, not a particular policy. Where a rule did decide the call, the record’s Policy tab already names it; where none acted, there is no policy to open. Either way, which policy to change is your call: open an existing one, or create a new one. With advanced logging on, the assistant can also read that call’s payload, which is what lets it name the fields involved. Without it, the call’s tool, connector and caller travel, but the field paths do not.Reviewing what it changed

Each field the assistant changed is marked AI, shows the value it replaced, and carries its own Accept and Revert.
Test a policy before enforcing it
Monitor only is how you check a rule before it refuses anything: the policy is consulted on every call it covers, and every call still goes through. There is no separate dry run. Leave a new deny rule in that mode until it covers what you intended.Save it Active, in Monitor only
Assign it to one user or group first
Make the calls it should cover
Switch it to Enforce
Manage policies
The Policies list shows each policy’s Applies to audience, Mode (Enforce or Monitor), Scope (Organization or This project), and Status. From a policy’s menu you can:- View and edit the rule. Saving a change writes a new version and keeps the previous one in the policy’s history.
- Duplicate it. The copy carries the same rule and audience, is named
<name> (copy), and lands Inactive and in Monitor only whatever the original was, so it does nothing until you have finished editing it. A policy whose rule the builder cannot read, or that holds more than one statement, cannot be duplicated, and the page says which. - Enforce or Stop enforcing to switch its mode.
- Activate or Deactivate to start or stop consulting it.
- Delete it, which also removes its version history. To stop a policy from acting without losing it, switch it to Monitor only or deactivate it instead.
What a denied call returns
When an enforced policy refuses a tool call, the request fails with HTTP403 before anything reaches the provider. The body names the level that refused it, not the rule:
org level means the refusal comes from an organization-wide policy, which a project member cannot change.
Troubleshooting
How do tool name patterns work?
How do tool name patterns work?
* is the only wildcard.? and [a-z] are literal. A pattern describes names, so *delete* matches tools named that way rather than every tool that deletes something.Why is a policy not taking effect?
Why is a policy not taking effect?
Can I see policy decisions in request logs?
Can I see policy decisions in request logs?
Why can I not create the policy?
Why can I not create the policy?
What does the AI mark on a field mean?
What does the AI mark on a field mean?
What does the generated rule look like?
What does the generated rule look like?
forbid on the invokeTool action, with when conditions for the targets and pattern and unless conditions for exemptions. JSON shows the same statement in Cedar’s JSON form. You cannot edit the statement directly; change the form and the preview follows.