policy.version | A/I/P/D: policy.version | A/I/P/D: policy.version | A/I/P/D: policy.version |
signature.sigil-envelope-v1 | A/D: signature.sigil-envelope-v1 | A/I/P/D: signature.sigil-envelope-v1 | A/D: signature.sigil-envelope-v1 |
profile.repository | A/I/P/D: profile.repository, profile.repository.roots, profile.repository.block_outside_writes, profile.repository.protect_git_history, profile.repository.protect_sensitive_files, profile.repository.git_providers, profile.repository.require_shim | A/I/P/D: profile.repository, profile.repository.roots, profile.repository.block_outside_writes, profile.repository.protect_git_history, profile.repository.protect_sensitive_files, profile.repository.git_providers, profile.repository.require_shim | A/I/P/D: profile.repository, profile.repository.roots, profile.repository.block_outside_writes, profile.repository.protect_git_history, profile.repository.protect_sensitive_files, profile.repository.git_providers, profile.repository.require_shim |
profile.filesystem | none: profile.filesystem, profile.filesystem.actions, profile.filesystem.write_roots, profile.filesystem.read_roots, profile.filesystem.allowed_effects, profile.filesystem.blocked_paths, profile.filesystem.protected_file_classes, profile.filesystem.protected_class_catalog, profile.filesystem.protected_effects, profile.filesystem.max_files_per_action, profile.filesystem.max_bytes_written_per_task, profile.filesystem.max_bytes_deleted_per_task, profile.filesystem.max_destructive_effects_per_task, profile.filesystem.require_shim | A/I/P/D: profile.filesystem, profile.filesystem.actions, profile.filesystem.write_roots, profile.filesystem.read_roots, profile.filesystem.allowed_effects, profile.filesystem.blocked_paths, profile.filesystem.protected_file_classes, profile.filesystem.protected_class_catalog, profile.filesystem.protected_effects, profile.filesystem.max_files_per_action, profile.filesystem.max_bytes_written_per_task, profile.filesystem.max_bytes_deleted_per_task, profile.filesystem.max_destructive_effects_per_task, profile.filesystem.require_shim | none: profile.filesystem, profile.filesystem.actions, profile.filesystem.write_roots, profile.filesystem.read_roots, profile.filesystem.allowed_effects, profile.filesystem.blocked_paths, profile.filesystem.protected_file_classes, profile.filesystem.protected_class_catalog, profile.filesystem.protected_effects, profile.filesystem.max_files_per_action, profile.filesystem.max_bytes_written_per_task, profile.filesystem.max_bytes_deleted_per_task, profile.filesystem.max_destructive_effects_per_task, profile.filesystem.require_shim |
profile.git | none: profile.git, profile.git.actions, profile.git.filesystem_actions, profile.git.providers, profile.git.allowed_remote_schemes, profile.git.allowed_operations, profile.git.require_approval, profile.git.blocked_operations, profile.git.protected_refs, profile.git.max_ref_changes_per_task, profile.git.require_shim | A/I/P/D: profile.git, profile.git.actions, profile.git.filesystem_actions, profile.git.providers, profile.git.allowed_remote_schemes, profile.git.allowed_operations, profile.git.require_approval, profile.git.blocked_operations, profile.git.protected_refs, profile.git.max_ref_changes_per_task, profile.git.require_shim | A/I/P/D: profile.git, profile.git.actions, profile.git.filesystem_actions, profile.git.providers, profile.git.allowed_remote_schemes, profile.git.allowed_operations, profile.git.require_approval, profile.git.blocked_operations, profile.git.protected_refs, profile.git.max_ref_changes_per_task, profile.git.require_shim |
profile.database | none: profile.database, profile.database.actions, profile.database.protected_environments, profile.database.allowed_operations, profile.database.require_approval, profile.database.allowed_resources, profile.database.routine_catalog, profile.database.require_read_only_for_select, profile.database.deny_unreviewed_indirect_effects, profile.database.max_schema_changes_per_task, profile.database.statement_timeout_ms, profile.database.lock_timeout_ms, profile.database.require_shim | A/I/P/D: profile.database, profile.database.actions, profile.database.protected_environments, profile.database.allowed_operations, profile.database.require_approval, profile.database.allowed_resources, profile.database.routine_catalog, profile.database.require_read_only_for_select, profile.database.deny_unreviewed_indirect_effects, profile.database.max_schema_changes_per_task, profile.database.statement_timeout_ms, profile.database.lock_timeout_ms, profile.database.require_shim | A/I/P/D: profile.database, profile.database.actions, profile.database.protected_environments, profile.database.allowed_operations, profile.database.require_approval, profile.database.allowed_resources, profile.database.routine_catalog, profile.database.require_read_only_for_select, profile.database.deny_unreviewed_indirect_effects, profile.database.max_schema_changes_per_task, profile.database.statement_timeout_ms, profile.database.lock_timeout_ms, profile.database.require_shim |
evm | A/I/P/D: evm.max_transaction_eth, evm.allowed_actions, evm.allowed_chains, evm.consensus_threshold_eth, evm.consensus_require_hold, evm.require_approval, evm.require_shim | A/I/P/D: evm.max_transaction_eth, evm.allowed_actions, evm.allowed_chains, evm.consensus_threshold_eth, evm.consensus_require_hold, evm.require_approval, evm.require_shim | A/I/P/D: evm.max_transaction_eth, evm.allowed_actions, evm.allowed_chains, evm.consensus_threshold_eth, evm.consensus_require_hold, evm.require_approval, evm.require_shim |
evm.chain_actions | I/P/D: evm.chain_actions | A/I/P/D: evm.chain_actions | A/I/P/D: evm.chain_actions |
evm.token | A/I/P/D: evm.token.*.max_transaction, evm.token.*.decimals, evm.token.*.addresses | A/I/P/D: evm.token.*.max_transaction, evm.token.*.decimals, evm.token.*.addresses | A/I/P/D: evm.token.*.max_transaction, evm.token.*.decimals, evm.token.*.addresses |
evm.token.consensus_threshold | none: evm.token.*.consensus_threshold | A/I/P/D: evm.token.*.consensus_threshold | none: evm.token.*.consensus_threshold |
evm.require_calldata_enrichment | none: evm.require_calldata_enrichment | A/I/P/D: evm.require_calldata_enrichment | none: evm.require_calldata_enrichment |
evm.calldata_unknown_selector | none: evm.calldata_unknown_selector | A/I/P/D: evm.calldata_unknown_selector | none: evm.calldata_unknown_selector |
tool_calls | A/I/P/D: tool_calls.allowed, tool_calls.bash.blocked_commands, tool_calls.web_fetch.blocked_domains, tool_calls.file_write.blocked_paths, tool_calls.email.require_approval, tool_calls.email.allowed_recipients, tool_calls.email.blocked_recipients, tool_calls.require_approval, tool_calls.require_shim | A/I/P/D: tool_calls.allowed, tool_calls.bash.blocked_commands, tool_calls.web_fetch.blocked_domains, tool_calls.file_write.blocked_paths, tool_calls.email.require_approval, tool_calls.email.allowed_recipients, tool_calls.email.blocked_recipients, tool_calls.require_approval, tool_calls.require_shim | A/I/P/D: tool_calls.allowed, tool_calls.bash.blocked_commands, tool_calls.web_fetch.blocked_domains, tool_calls.file_write.blocked_paths, tool_calls.email.require_approval, tool_calls.email.allowed_recipients, tool_calls.email.blocked_recipients, tool_calls.require_approval, tool_calls.require_shim |
tool_calls.http | A/I/P/D: tool_calls.http.allowed_methods, tool_calls.http.blocked_methods, tool_calls.http.allowed_hosts | A/I/P/D: tool_calls.http.allowed_methods, tool_calls.http.blocked_methods, tool_calls.http.allowed_hosts | A/I/P/D: tool_calls.http.allowed_methods, tool_calls.http.blocked_methods, tool_calls.http.allowed_hosts |
tool_calls.http.method_rules | none: tool_calls.http.method_rules, tool_calls.http.method_rules.*.require_query_matches, tool_calls.http.method_rules.*.deny | A/I/P/D: tool_calls.http.method_rules, tool_calls.http.method_rules.*.require_query_matches, tool_calls.http.method_rules.*.deny | none: tool_calls.http.method_rules, tool_calls.http.method_rules.*.require_query_matches, tool_calls.http.method_rules.*.deny |
mcp | A/I/P/D: mcp.allowed_servers, mcp.allowed_tools, mcp.blocked_tools, mcp.require_approval, mcp.require_shim | A/I/P/D: mcp.allowed_servers, mcp.allowed_tools, mcp.blocked_tools, mcp.require_approval, mcp.require_shim | A/I/P/D: mcp.allowed_servers, mcp.allowed_tools, mcp.blocked_tools, mcp.require_approval, mcp.require_shim |
mcp.response.web_fetch_tools | A/I/P/D: mcp.response.web_fetch_tools | A/I/P/D: mcp.response.web_fetch_tools | A/I/P/D: mcp.response.web_fetch_tools |
mcp.response.http_tools | A/I/P/D: mcp.response.http_tools | A/I/P/D: mcp.response.http_tools | A/I/P/D: mcp.response.http_tools |
mcp.response.deterministic_ruleset | A/I/P/D: mcp.response.deterministic_ruleset | A/I/P/D: mcp.response.deterministic_ruleset | A/I/P/D: mcp.response.deterministic_ruleset |
mcp.response.block_classes | A/I/P/D: mcp.response.block_classes | A/I/P/D: mcp.response.block_classes | A/I/P/D: mcp.response.block_classes |
custom | A/I/P/D: custom.allow_only, custom.deny_if, custom.deny_string, custom.require_approval, custom.require_shim | A/I/P/D: custom.allow_only, custom.deny_if, custom.deny_string, custom.require_approval, custom.require_shim | A/I/P/D: custom.allow_only, custom.deny_if, custom.deny_string, custom.require_approval, custom.require_shim |
custom.response.deny_string | A/I/P/D: custom.response.deny_string | A/I/P/D: custom.response.deny_string | A/I/P/D: custom.response.deny_string |
soft_limits | A/I/P/D: soft_limits.daily_evm_limit_eth, soft_limits.daily_tool_calls, soft_limits.require_approval, soft_limits.require_shim | A/I/P/D: soft_limits.daily_evm_limit_eth, soft_limits.daily_tool_calls, soft_limits.require_approval, soft_limits.require_shim | A/I/P/D: soft_limits.daily_evm_limit_eth, soft_limits.daily_tool_calls, soft_limits.require_approval, soft_limits.require_shim |
soft_limits.cap | A/I/P/D: soft_limits.cap.*.max_count, soft_limits.cap.*.max_sum_usd, soft_limits.cap.*.window, soft_limits.cap.*.action, soft_limits.cap.*.group_by, soft_limits.cap.*.amount_field | A/I/P/D: soft_limits.cap.*.max_count, soft_limits.cap.*.max_sum_usd, soft_limits.cap.*.window, soft_limits.cap.*.action, soft_limits.cap.*.group_by, soft_limits.cap.*.amount_field | A/I/P/D: soft_limits.cap.*.max_count, soft_limits.cap.*.max_sum_usd, soft_limits.cap.*.window, soft_limits.cap.*.action, soft_limits.cap.*.group_by, soft_limits.cap.*.amount_field |
execution_limits | A/I/P/D: execution_limits.max_tool_calls_per_task, execution_limits.max_tool_calls_per_hour, execution_limits.max_model_spend_usd_per_task, execution_limits.max_model_tokens_per_task | A/I/P/D: execution_limits.max_tool_calls_per_task, execution_limits.max_tool_calls_per_hour, execution_limits.max_model_spend_usd_per_task, execution_limits.max_model_tokens_per_task | A/I/P/D: execution_limits.max_tool_calls_per_task, execution_limits.max_tool_calls_per_hour, execution_limits.max_model_spend_usd_per_task, execution_limits.max_model_tokens_per_task |
execution_limits.require_approval | A/I/P/D: execution_limits.require_approval | A/I/P/D: execution_limits.require_approval | A/I/P/D: execution_limits.require_approval |
execution_limits.require_shim | A/I/P/D: execution_limits.require_shim | A/I/P/D: execution_limits.require_shim | A/I/P/D: execution_limits.require_shim |