Policy templates¶
Starting points to copy and adapt. Each is checked by the test suite. Inspect any of them
with agentguard explain before use.
Coding agent¶
Works inside ./workspace, runs commands (pair it with an allowlisting ShellExecutor),
asks before deleting files, pushing, or running commands in production.
examples/policies/coding-agent.yaml
# Coding agent: works inside ./workspace, runs allowlisted commands, asks before
# deleting or touching the remote. Pair shell tools with ShellExecutor so only exact,
# administrator-approved commands can run.
version: 1
defaults:
effect: deny
rules:
- capability: filesystem.read
paths: ["./workspace/**"]
effect: allow
- capability: filesystem.write
paths: ["./workspace/**"]
effect: allow
- capability: filesystem.delete
paths: ["./workspace/**"]
effect: ask
- capability: shell.execute
environment: production
effect: ask
- capability: shell.execute
effect: allow
- capability: repository.write
effect: ask
- capability: network.request
domains: ["docs.python.org", "pypi.org", "*.github.com"]
effect: allow
- capability: network.request
sensitive_data: [api_key, password, ssh_key, jwt, database_url]
effect: deny
risk:
ask: 51
strong: 76
deny: 91
limits:
max_calls_per_minute: 120
max_argument_bytes: 262144
Browsing agent¶
Reads an allowlist of sites, saves to ./downloads, never sends credentials. Pair fetch
tools with NetworkExecutor.
examples/policies/browsing-agent.yaml
# Browsing/research agent: reads an allowlist of sites, saves notes to ./downloads,
# never sends credentials anywhere. Pair fetch tools with NetworkExecutor for
# HTTPS-only GETs with private-address rejection.
version: 1
defaults:
effect: deny
rules:
- capability: network.request
sensitive_data: [api_key, password, ssh_key, jwt, database_url]
effect: deny
- capability: network.request
domains: ["en.wikipedia.org", "docs.python.org", "*.readthedocs.io", "arxiv.org"]
effect: allow
- capability: filesystem.write
paths: ["./downloads/**"]
effect: allow
- capability: filesystem.read
paths: ["./downloads/**"]
effect: allow
- capability: message.send
effect: ask
limits:
max_calls_per_minute: 60
max_recipients_per_action: 1
Support agent¶
Uses custom capabilities for a CRM and refunds. Replies go out to one customer at a time; refunds need a human.
examples/policies/support-agent.yaml
# Customer-support agent: reads the CRM freely, updates it, replies to one customer at
# a time, and needs a human for refunds. Custom capabilities declare their own risk.
version: 1
defaults:
effect: deny
capabilities:
crm.read:
risk: 10
description: Look up customers, orders and tickets
crm.update:
risk: 35
description: Change ticket status, tags and notes
payments.refund:
risk: 70
outbound: true
description: Refund an order to the original payment method
rules:
- capability: crm.read
effect: allow
- capability: crm.update
effect: allow
- capability: payments.refund
environment: production
effect: ask
- capability: payments.refund
effect: allow
- capability: email.send
sensitive_data: [api_key, password, jwt, database_url]
effect: deny
- capability: email.send
effect: allow
risk:
# Customer replies (email.send, baseline 55) proceed; refunds (70, or 85 in
# production) need ordinary human approval.
ask: 60
strong: 90
deny: 97
limits:
max_calls_per_minute: 60
max_recipients_per_action: 1
agentguard explain examples/policies/support-agent.yaml payments.refund --arg order_id=o-1 --env production