Use one policy across your agents
Choose one account-wide policy and verify how it behaves across different integrations.
Agent Approve keeps one policy active for your account. Connected integrations in Approval Mode use that policy instead of maintaining a separate list for each coding tool.
Choose a starting policy
- Open Policy in the iOS app.
- Open the policy selector.
- Choose Permissive when common low-risk commands should continue automatically and other actions should ask you.
- Choose Restrictive when you also want the shipped destructive patterns denied automatically.
- Duplicate a policy before making substantial changes so you can return to the shipped version.
Read Policies and default behavior before using Allow All, Deny All, or one of the exception-based policies.
Add rules that travel with you
Use Remember decisions during an approval or edit the active policy directly. A remembered approval adds a rule to the Allow List. A remembered denial adds a rule to the Deny List.
Choose the narrowest useful scope. A rule for one exact command or command prefix is safer than allowing every input to a shell tool. A Contains rule can match text in an unexpected position, so test it with harmless requests before leaving agents unattended.
Verify more than one integration
- Confirm the intended policy is active.
- Send a harmless, unmatched request from one connected agent and review the result.
- Send an equivalent harmless request from a second integration.
- Open each event and confirm which rule or default behavior made the decision.
The same policy does not make every integration identical. Agents report different tool names, inputs, and event types, so a rule that matches one integration may need a different scope for another. Use the capability matrix and test important rules with harmless requests.
The active policy is currently account-wide. You cannot select a different active policy for one agent, computer, or Hermes profile.