Skip to content

Policies

A policy says what workers may do with a tool: allow, notify, require approval or deny. The most specific policy wins.

EffectsLink to Effects

  • Allow: the worker acts on its own.
  • Notify: the worker acts, then tells people.
  • Require approval: a person approves before it runs.
  • Deny: never allowed.

Which policy winsLink to Which policy wins

The most specific scope wins: worker, then role, team and organization. Priority breaks ties within a scope. When a tie remains, deny wins. A call that no policy matches gets the default for its risk tier.

DefaultsLink to Defaults

Without policies, reads run, messages notify, merges and deploys need approval, and destructive actions are refused.

The pageLink to The page

Policies has two tabs: Rules and Simulator. Use the simulator to test which policy applies to a call. Only owners and admins can add, enable or disable a policy.

Checked against the product on 2026-10-05.

Was this helpful?