> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sigilcore.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Archived Policy 2.1 authoring capability matrix

> The immutable authoring capability matrix for the Policy 2.1 Warrant Core 0.2.1 contract.

# Archived Policy 2.1 authoring capability matrix

This matrix is retained for operators maintaining Policy 2.1 Warrants. It is an archive of the generated `@sigilcore/warrant-core@0.2.1` authoring contract and is not regenerated from the current Policy 2.3 package.

Source: `@sigilcore/warrant-core@0.2.1`, `AUTHORING_CAPABILITY_MANIFEST` (capability schema v1).

Legend: A = author, I = import, P = preserve without loss, D = deploy. `none` means the surface rejects that field before mutating policy state.

| Deploy feature                      | Manual Form                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Manual Advanced                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Warrant Builder                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `policy.version`                    | `A/I/P/D`: `policy.version`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | `A/I/P/D`: `policy.version`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | `A/I/P/D`: `policy.version`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `signature.sigil-envelope-v1`       | `A/D`: `signature.sigil-envelope-v1`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | `A/I/P/D`: `signature.sigil-envelope-v1`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | `A/D`: `signature.sigil-envelope-v1`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `profile.repository`                | `A/I/P/D`: `profile.repository`, `profile.repository.roots`, `profile.repository.block_outside_writes`, `profile.repository.protect_git_history`, `profile.repository.protect_sensitive_files`, `profile.repository.git_providers`, `profile.repository.require_shim`                                                                                                                                                                                                                                                                                                             | `A/I/P/D`: `profile.repository`, `profile.repository.roots`, `profile.repository.block_outside_writes`, `profile.repository.protect_git_history`, `profile.repository.protect_sensitive_files`, `profile.repository.git_providers`, `profile.repository.require_shim`                                                                                                                                                                                                                                                                                                                | `A/I/P/D`: `profile.repository`, `profile.repository.roots`, `profile.repository.block_outside_writes`, `profile.repository.protect_git_history`, `profile.repository.protect_sensitive_files`, `profile.repository.git_providers`, `profile.repository.require_shim`                                                                                                                                                                                                                                                                                                             |
| `profile.filesystem`                | `none`: `profile.filesystem`, `profile.filesystem.actions`, `profile.filesystem.write_roots`, `profile.filesystem.read_roots`, `profile.filesystem.allowed_effects`, `profile.filesystem.blocked_paths`, `profile.filesystem.protected_file_classes`, `profile.filesystem.protected_class_catalog`, `profile.filesystem.protected_effects`, `profile.filesystem.max_files_per_action`, `profile.filesystem.max_bytes_written_per_task`, `profile.filesystem.max_bytes_deleted_per_task`, `profile.filesystem.max_destructive_effects_per_task`, `profile.filesystem.require_shim` | `A/I/P/D`: `profile.filesystem`, `profile.filesystem.actions`, `profile.filesystem.write_roots`, `profile.filesystem.read_roots`, `profile.filesystem.allowed_effects`, `profile.filesystem.blocked_paths`, `profile.filesystem.protected_file_classes`, `profile.filesystem.protected_class_catalog`, `profile.filesystem.protected_effects`, `profile.filesystem.max_files_per_action`, `profile.filesystem.max_bytes_written_per_task`, `profile.filesystem.max_bytes_deleted_per_task`, `profile.filesystem.max_destructive_effects_per_task`, `profile.filesystem.require_shim` | `none`: `profile.filesystem`, `profile.filesystem.actions`, `profile.filesystem.write_roots`, `profile.filesystem.read_roots`, `profile.filesystem.allowed_effects`, `profile.filesystem.blocked_paths`, `profile.filesystem.protected_file_classes`, `profile.filesystem.protected_class_catalog`, `profile.filesystem.protected_effects`, `profile.filesystem.max_files_per_action`, `profile.filesystem.max_bytes_written_per_task`, `profile.filesystem.max_bytes_deleted_per_task`, `profile.filesystem.max_destructive_effects_per_task`, `profile.filesystem.require_shim` |
| `profile.git`                       | `none`: `profile.git`, `profile.git.actions`, `profile.git.filesystem_actions`, `profile.git.providers`, `profile.git.allowed_remote_schemes`, `profile.git.allowed_operations`, `profile.git.require_approval`, `profile.git.blocked_operations`, `profile.git.protected_refs`, `profile.git.max_ref_changes_per_task`, `profile.git.require_shim`                                                                                                                                                                                                                               | `A/I/P/D`: `profile.git`, `profile.git.actions`, `profile.git.filesystem_actions`, `profile.git.providers`, `profile.git.allowed_remote_schemes`, `profile.git.allowed_operations`, `profile.git.require_approval`, `profile.git.blocked_operations`, `profile.git.protected_refs`, `profile.git.max_ref_changes_per_task`, `profile.git.require_shim`                                                                                                                                                                                                                               | `A/I/P/D`: `profile.git`, `profile.git.actions`, `profile.git.filesystem_actions`, `profile.git.providers`, `profile.git.allowed_remote_schemes`, `profile.git.allowed_operations`, `profile.git.require_approval`, `profile.git.blocked_operations`, `profile.git.protected_refs`, `profile.git.max_ref_changes_per_task`, `profile.git.require_shim`                                                                                                                                                                                                                            |
| `profile.database`                  | `none`: `profile.database`, `profile.database.actions`, `profile.database.protected_environments`, `profile.database.allowed_operations`, `profile.database.require_approval`, `profile.database.allowed_resources`, `profile.database.routine_catalog`, `profile.database.require_read_only_for_select`, `profile.database.deny_unreviewed_indirect_effects`, `profile.database.max_schema_changes_per_task`, `profile.database.statement_timeout_ms`, `profile.database.lock_timeout_ms`, `profile.database.require_shim`                                                       | `A/I/P/D`: `profile.database`, `profile.database.actions`, `profile.database.protected_environments`, `profile.database.allowed_operations`, `profile.database.require_approval`, `profile.database.allowed_resources`, `profile.database.routine_catalog`, `profile.database.require_read_only_for_select`, `profile.database.deny_unreviewed_indirect_effects`, `profile.database.max_schema_changes_per_task`, `profile.database.statement_timeout_ms`, `profile.database.lock_timeout_ms`, `profile.database.require_shim`                                                       | `A/I/P/D`: `profile.database`, `profile.database.actions`, `profile.database.protected_environments`, `profile.database.allowed_operations`, `profile.database.require_approval`, `profile.database.allowed_resources`, `profile.database.routine_catalog`, `profile.database.require_read_only_for_select`, `profile.database.deny_unreviewed_indirect_effects`, `profile.database.max_schema_changes_per_task`, `profile.database.statement_timeout_ms`, `profile.database.lock_timeout_ms`, `profile.database.require_shim`                                                    |
| `evm`                               | `A/I/P/D`: `evm.max_transaction_eth`, `evm.allowed_actions`, `evm.allowed_chains`, `evm.consensus_threshold_eth`, `evm.consensus_require_hold`, `evm.require_approval`, `evm.require_shim`                                                                                                                                                                                                                                                                                                                                                                                        | `A/I/P/D`: `evm.max_transaction_eth`, `evm.allowed_actions`, `evm.allowed_chains`, `evm.consensus_threshold_eth`, `evm.consensus_require_hold`, `evm.require_approval`, `evm.require_shim`                                                                                                                                                                                                                                                                                                                                                                                           | `A/I/P/D`: `evm.max_transaction_eth`, `evm.allowed_actions`, `evm.allowed_chains`, `evm.consensus_threshold_eth`, `evm.consensus_require_hold`, `evm.require_approval`, `evm.require_shim`                                                                                                                                                                                                                                                                                                                                                                                        |
| `evm.chain_actions`                 | `I/P/D`: `evm.chain_actions`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | `A/I/P/D`: `evm.chain_actions`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | `A/I/P/D`: `evm.chain_actions`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `evm.token`                         | `A/I/P/D`: `evm.token.*.max_transaction`, `evm.token.*.decimals`, `evm.token.*.addresses`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | `A/I/P/D`: `evm.token.*.max_transaction`, `evm.token.*.decimals`, `evm.token.*.addresses`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | `A/I/P/D`: `evm.token.*.max_transaction`, `evm.token.*.decimals`, `evm.token.*.addresses`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `evm.token.consensus_threshold`     | `none`: `evm.token.*.consensus_threshold`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | `A/I/P/D`: `evm.token.*.consensus_threshold`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | `none`: `evm.token.*.consensus_threshold`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `evm.require_calldata_enrichment`   | `none`: `evm.require_calldata_enrichment`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | `A/I/P/D`: `evm.require_calldata_enrichment`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | `none`: `evm.require_calldata_enrichment`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `evm.calldata_unknown_selector`     | `none`: `evm.calldata_unknown_selector`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | `A/I/P/D`: `evm.calldata_unknown_selector`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | `none`: `evm.calldata_unknown_selector`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `tool_calls`                        | `A/I/P/D`: `tool_calls.allowed`, `tool_calls.bash.blocked_commands`, `tool_calls.web_fetch.blocked_domains`, `tool_calls.file_write.blocked_paths`, `tool_calls.email.require_approval`, `tool_calls.email.allowed_recipients`, `tool_calls.email.blocked_recipients`, `tool_calls.require_approval`, `tool_calls.require_shim`                                                                                                                                                                                                                                                   | `A/I/P/D`: `tool_calls.allowed`, `tool_calls.bash.blocked_commands`, `tool_calls.web_fetch.blocked_domains`, `tool_calls.file_write.blocked_paths`, `tool_calls.email.require_approval`, `tool_calls.email.allowed_recipients`, `tool_calls.email.blocked_recipients`, `tool_calls.require_approval`, `tool_calls.require_shim`                                                                                                                                                                                                                                                      | `A/I/P/D`: `tool_calls.allowed`, `tool_calls.bash.blocked_commands`, `tool_calls.web_fetch.blocked_domains`, `tool_calls.file_write.blocked_paths`, `tool_calls.email.require_approval`, `tool_calls.email.allowed_recipients`, `tool_calls.email.blocked_recipients`, `tool_calls.require_approval`, `tool_calls.require_shim`                                                                                                                                                                                                                                                   |
| `tool_calls.http`                   | `A/I/P/D`: `tool_calls.http.allowed_methods`, `tool_calls.http.blocked_methods`, `tool_calls.http.allowed_hosts`                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | `A/I/P/D`: `tool_calls.http.allowed_methods`, `tool_calls.http.blocked_methods`, `tool_calls.http.allowed_hosts`                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | `A/I/P/D`: `tool_calls.http.allowed_methods`, `tool_calls.http.blocked_methods`, `tool_calls.http.allowed_hosts`                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `tool_calls.http.method_rules`      | `none`: `tool_calls.http.method_rules`, `tool_calls.http.method_rules.*.require_query_matches`, `tool_calls.http.method_rules.*.deny`                                                                                                                                                                                                                                                                                                                                                                                                                                             | `A/I/P/D`: `tool_calls.http.method_rules`, `tool_calls.http.method_rules.*.require_query_matches`, `tool_calls.http.method_rules.*.deny`                                                                                                                                                                                                                                                                                                                                                                                                                                             | `none`: `tool_calls.http.method_rules`, `tool_calls.http.method_rules.*.require_query_matches`, `tool_calls.http.method_rules.*.deny`                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| `mcp`                               | `A/I/P/D`: `mcp.allowed_servers`, `mcp.allowed_tools`, `mcp.blocked_tools`, `mcp.require_approval`, `mcp.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                            | `A/I/P/D`: `mcp.allowed_servers`, `mcp.allowed_tools`, `mcp.blocked_tools`, `mcp.require_approval`, `mcp.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                               | `A/I/P/D`: `mcp.allowed_servers`, `mcp.allowed_tools`, `mcp.blocked_tools`, `mcp.require_approval`, `mcp.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `custom`                            | `A/I/P/D`: `custom.allow_only`, `custom.deny_if`, `custom.deny_string`, `custom.require_approval`, `custom.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                          | `A/I/P/D`: `custom.allow_only`, `custom.deny_if`, `custom.deny_string`, `custom.require_approval`, `custom.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                             | `A/I/P/D`: `custom.allow_only`, `custom.deny_if`, `custom.deny_string`, `custom.require_approval`, `custom.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `soft_limits`                       | `A/I/P/D`: `soft_limits.daily_evm_limit_eth`, `soft_limits.daily_tool_calls`, `soft_limits.require_approval`, `soft_limits.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                          | `A/I/P/D`: `soft_limits.daily_evm_limit_eth`, `soft_limits.daily_tool_calls`, `soft_limits.require_approval`, `soft_limits.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                             | `A/I/P/D`: `soft_limits.daily_evm_limit_eth`, `soft_limits.daily_tool_calls`, `soft_limits.require_approval`, `soft_limits.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `soft_limits.cap`                   | `A/I/P/D`: `soft_limits.cap.*.max_count`, `soft_limits.cap.*.max_sum_usd`, `soft_limits.cap.*.window`, `soft_limits.cap.*.action`, `soft_limits.cap.*.group_by`, `soft_limits.cap.*.amount_field`                                                                                                                                                                                                                                                                                                                                                                                 | `A/I/P/D`: `soft_limits.cap.*.max_count`, `soft_limits.cap.*.max_sum_usd`, `soft_limits.cap.*.window`, `soft_limits.cap.*.action`, `soft_limits.cap.*.group_by`, `soft_limits.cap.*.amount_field`                                                                                                                                                                                                                                                                                                                                                                                    | `A/I/P/D`: `soft_limits.cap.*.max_count`, `soft_limits.cap.*.max_sum_usd`, `soft_limits.cap.*.window`, `soft_limits.cap.*.action`, `soft_limits.cap.*.group_by`, `soft_limits.cap.*.amount_field`                                                                                                                                                                                                                                                                                                                                                                                 |
| `execution_limits`                  | `A/I/P/D`: `execution_limits.max_tool_calls_per_task`, `execution_limits.max_tool_calls_per_hour`, `execution_limits.max_model_spend_usd_per_task`, `execution_limits.max_model_tokens_per_task`                                                                                                                                                                                                                                                                                                                                                                                  | `A/I/P/D`: `execution_limits.max_tool_calls_per_task`, `execution_limits.max_tool_calls_per_hour`, `execution_limits.max_model_spend_usd_per_task`, `execution_limits.max_model_tokens_per_task`                                                                                                                                                                                                                                                                                                                                                                                     | `A/I/P/D`: `execution_limits.max_tool_calls_per_task`, `execution_limits.max_tool_calls_per_hour`, `execution_limits.max_model_spend_usd_per_task`, `execution_limits.max_model_tokens_per_task`                                                                                                                                                                                                                                                                                                                                                                                  |
| `execution_limits.require_approval` | `A/I/P/D`: `execution_limits.require_approval`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | `A/I/P/D`: `execution_limits.require_approval`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | `A/I/P/D`: `execution_limits.require_approval`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `execution_limits.require_shim`     | `A/I/P/D`: `execution_limits.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | `A/I/P/D`: `execution_limits.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | `A/I/P/D`: `execution_limits.require_shim`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |

This archived matrix is evidence for the Policy 2.1 contract only. Use the [current Policy 2.3 authoring capability matrix](policy-2-3.md#authoring-capability-matrix) for new Warrants.
