Policy Enforcement Layers
Policies are evaluated at multiple layers:Minimal Policy
Start with the minimum required fields:Tool Allowlists
Control which tools agents can invoke:Enforcement Rules
Define which violations trigger a deny:skill_*), see Skills Hooks.
Observe vs Enforce
Privacy Controls
Side-Effect Controls
Agent Guard
Configure content scanning thresholds:Signing
Observability
Boundary Security
Gateway-level security controls:Export
Full Policy Example
Validating Policy
Usesec0-sdk/policy to validate a policy before deployment:
Policy Sources
Policies can be loaded from multiple sources:
For the full policy schema reference, see Policy Schema Reference.