Skip to content

Policy templates

Starting points to copy and adapt. Each is checked by the test suite. Inspect any of them with agentguard explain before use.

Coding agent

Works inside ./workspace, runs commands (pair it with an allowlisting ShellExecutor), asks before deleting files, pushing, or running commands in production.

examples/policies/coding-agent.yaml
# Coding agent: works inside ./workspace, runs allowlisted commands, asks before
# deleting or touching the remote. Pair shell tools with ShellExecutor so only exact,
# administrator-approved commands can run.
version: 1
defaults:
  effect: deny
rules:
  - capability: filesystem.read
    paths: ["./workspace/**"]
    effect: allow
  - capability: filesystem.write
    paths: ["./workspace/**"]
    effect: allow
  - capability: filesystem.delete
    paths: ["./workspace/**"]
    effect: ask
  - capability: shell.execute
    environment: production
    effect: ask
  - capability: shell.execute
    effect: allow
  - capability: repository.write
    effect: ask
  - capability: network.request
    domains: ["docs.python.org", "pypi.org", "*.github.com"]
    effect: allow
  - capability: network.request
    sensitive_data: [api_key, password, ssh_key, jwt, database_url]
    effect: deny
risk:
  ask: 51
  strong: 76
  deny: 91
limits:
  max_calls_per_minute: 120
  max_argument_bytes: 262144

Browsing agent

Reads an allowlist of sites, saves to ./downloads, never sends credentials. Pair fetch tools with NetworkExecutor.

examples/policies/browsing-agent.yaml
# Browsing/research agent: reads an allowlist of sites, saves notes to ./downloads,
# never sends credentials anywhere. Pair fetch tools with NetworkExecutor for
# HTTPS-only GETs with private-address rejection.
version: 1
defaults:
  effect: deny
rules:
  - capability: network.request
    sensitive_data: [api_key, password, ssh_key, jwt, database_url]
    effect: deny
  - capability: network.request
    domains: ["en.wikipedia.org", "docs.python.org", "*.readthedocs.io", "arxiv.org"]
    effect: allow
  - capability: filesystem.write
    paths: ["./downloads/**"]
    effect: allow
  - capability: filesystem.read
    paths: ["./downloads/**"]
    effect: allow
  - capability: message.send
    effect: ask
limits:
  max_calls_per_minute: 60
  max_recipients_per_action: 1

Support agent

Uses custom capabilities for a CRM and refunds. Replies go out to one customer at a time; refunds need a human.

examples/policies/support-agent.yaml
# Customer-support agent: reads the CRM freely, updates it, replies to one customer at
# a time, and needs a human for refunds. Custom capabilities declare their own risk.
version: 1
defaults:
  effect: deny
capabilities:
  crm.read:
    risk: 10
    description: Look up customers, orders and tickets
  crm.update:
    risk: 35
    description: Change ticket status, tags and notes
  payments.refund:
    risk: 70
    outbound: true
    description: Refund an order to the original payment method
rules:
  - capability: crm.read
    effect: allow
  - capability: crm.update
    effect: allow
  - capability: payments.refund
    environment: production
    effect: ask
  - capability: payments.refund
    effect: allow
  - capability: email.send
    sensitive_data: [api_key, password, jwt, database_url]
    effect: deny
  - capability: email.send
    effect: allow
risk:
  # Customer replies (email.send, baseline 55) proceed; refunds (70, or 85 in
  # production) need ordinary human approval.
  ask: 60
  strong: 90
  deny: 97
limits:
  max_calls_per_minute: 60
  max_recipients_per_action: 1
agentguard explain examples/policies/support-agent.yaml payments.refund --arg order_id=o-1 --env production