Skip to main content
Documentation
Docs / Products / Rules
Agent setup

Control

Rules

Compare proposed actions with an explicit authority contract covering paths, commands, hosts, and budget.

Last updated August 22, 2026

Review an agent action before it exceeds the brief.

Use cases

Keep scope inspectable

See the rule behind an allow, deny, unknown, or approval-required result.

Expose missing authority

Uncovered actions remain visible so someone can resolve the boundary.

Make approval specific

Review the proposed action and its scope before granting additional authority.

How it works

  1. 1

    Define the boundary

    Supply the authority contract for the task.

  2. 2

    List proposed actions

    Include the actual paths, commands, or hosts the agent intends to use.

  3. 3

    Review the decisions

    Resolve denied, unknown, or approval-required actions in your execution workflow.

Quickstart

Open Rules in the console, provide the required inputs, and start an organization scoped run.

Inputs

  • task plan
  • repository
  • policy rules
  • proposed actions

Outputs

  • signed authority contract
  • policy decisions
  • expansion requests
  • scope receipt
Open Rules

MCP

Call Rules from a compatible agent with the preferred public tool name.

bashReady
symbolic.guard.run

The previous internal service identifier remains accepted for compatibility, but new integrations should use this product name.