Change the access policy
Publish workspace presets and custom metadata rules.
Publish a policy
In the Admin workspace, open Policies and Default access.
- Choose Allow reviewed requests or Deny all tool access.
- Choose Allow reviewed writes, Require another administrator, or Deny all writes.
- Review the scope and select Publish policy.
- Check the saved version, then test an intended allowed case and a denied case. Use a supported sandbox fixture for write tests.
Add custom rules
Open Custom policies and Edit custom policies. Add a draft rule, edit its JSON conditions, test the draft, then publish. Rules can match people, clients, environments, connections, providers, reviewed tools, actions and mapped resources. Copy JSON to export; paste it to import. Removing a rule takes effect only when you publish. Custom allows cannot override required checks, workspace presets or team restrictions. This bounded Durin DSL is not Rego.
Troubleshooting
Writes are allowed but the request is denied
Check Default access first: Deny all tool access blocks reads and writes. Then inspect the request’s failed membership, credential, resource, review, or team check.
Frequently asked questions
Can team policy weaken an organization denial?
No. Team policy can inherit or impose stricter restrictions.