Skip to main content
Define allow/deny rules so agents cannot run dangerous tools — attach a PolicyEngine before the agent starts.
The user requests a risky action; policy rules allow or deny tools before execution.

Quick Start

1

Simple Usage

Block delete tools on a file-management agent:
2

With Configuration

Use strict mode and custom deny lists:

How It Works

ComponentPurpose
PolicyRuleWildcard resource patterns with ALLOW, DENY, ASK, or LOG
PolicyEngineEvaluates rules by priority; optional strict mode
agent.policyAttach the engine before start()
Pattern examples: tool:read_file, tool:delete_*, tool:*.

Configuration Options

OptionTypeDefaultDescription
strict_modeboolFalseDeny operations not explicitly allowed
actionPolicyActionALLOW, DENY, ASK, LOG, RATE_LIMIT
resourcestrNoneGlob pattern (e.g. tool:shell_*)
priorityint0Higher priority rules evaluate first

Best Practices

Set agent.policy = engine immediately after creating the agent.
Use create_read_only_policy() before writing custom rules.
Prefer tool:delete_* over tool:* deny rules so read tools keep working.
PolicyConfig(strict_mode=True) blocks unknown tool names by default.

Guardrails

Validate agent output before returning to users

Approval

Require human confirmation for sensitive actions