durin
Sign up
Policies & approvals

Understanding policy decisions

Read the allowed, denied, and approval-required results.

Required checks come first

Every request must pass current identity, membership, connection, team, credential, reviewed tool, resource, and inspection checks. A configurable allow setting cannot override a failed check. Team restrictions can narrow organization policy.

The three decisions

The decision describes authorization, not provider success.

  • Allowed: the request may proceed; inspect execution separately.
  • Denied: the request does not execute. Read the reason before changing settings.
  • Approval-required: the action has not executed. A different administrator must review it, then the requester retries the exact call before expiry.

Frequently asked questions

Are reads always allowed?

No. Default deny can block reads and writes. Reviewed reads under default allow still need all mandatory checks.

Do production and sandbox use different write rules?

Workspace presets apply to both. Custom rules can add stricter conditions for a specific environment, such as approval for production writes. Production still requires reviewed tools and current provider authorization.

Try Durin with your MCP workflow.

Create an account to connect a client, route governed MCP requests, and review decisions with your admins.

Create an account