Skip to main content
policy.yaml is the main file a developer authors to tell Sec0 what is allowed, what must be denied, and how telemetry and side effects should be handled. This page keeps the parts of the schema that are typically written as part of an SDK integration.

Minimal example

Top-level

Compliance pack authoring and export settings are intentionally not part of the main developer reference. Use the dedicated compliance and operations docs for those flows.

signing

observability

observability.sample

tools

skills

privacy

side_effects

enforcement

enforcement.deny_on and enforcement.escalate_on values

enforcement.circuit_breakers

agent_guard

This is the preferred place for guard thresholds.

security

Use security when the same policy document should also drive gateway-style runtime guardrails.

security.limits

security.side_effects

security.side_effects.human_escalation / humanEscalation