Understanding policy decisions
Read the allowed, denied, and approval-required results.
Required checks come first
Every request must pass current identity, membership, connection, team, credential, reviewed tool, resource, and inspection checks. A configurable allow setting cannot override a failed check. Team restrictions can narrow organization policy.
The three decisions
The decision describes authorization, not provider success.
- Allowed: the request may proceed; inspect execution separately.
- Denied: the request does not execute. Read the reason before changing settings.
- Approval-required: the action has not executed. A different administrator must review it, then the requester retries the exact call before expiry.
Frequently asked questions
Are reads always allowed?
No. Default deny can block reads and writes. Reviewed reads under default allow still need all mandatory checks.
Do production and sandbox use different write rules?
Workspace presets apply to both. Custom rules can add stricter conditions for a specific environment, such as approval for production writes. Production still requires reviewed tools and current provider authorization.