Policy presets

Add ready-made restrictions for commands and tools, review the exact matches, and publish them to your workspace or account.

On this page

Policy presets are ready-made starting points for common restrictions. Add one or combine several in Dashboard → Policies. Each preset adds blocked tools or command patterns to the draft you are editing.

Add and customize a preset

  1. Choose Org default, Member overrides, or your own Access controls, depending on your workspace role. When editing a member override, select the member first.
  2. In Policy presets, select Add to policy. Use Browse all 17 presets to see the complete library and Details to open the matching section below.
  3. Review Blocked tools and Blocked command patterns. Existing entries stay in place and duplicate entries are skipped. Added means all of that preset's entries are in this draft; it does not mean the policy has been saved or synchronized.
  4. Review the policy mode and any Advanced rules, then select Save. Adding a preset does not change the mode or publish anything by itself.
  5. Run beam sync on a connected test device and verify the intended assistant's hook response with a harmless fixture.

Use Discard to revert an unsaved draft. To customize or remove an individual restriction, turn off its tool toggle or edit its pattern line, then save. Presets are copied settings, not subscriptions: future catalog edits do not silently update policies you already saved.

Member overrides add restrictions on top of the organization policy. Removing a restriction from an override does not remove the same restriction from the organization policy. The editor permits at most 40 blocked tools and 60 command patterns; an addition that exceeds those limits is rejected without changing the draft.

Choose the matching behavior

ModeEffect of these presets
ObserveStore the settings without enforcing workspace restrictions.
AdvisoryProduce an approval decision for a matching preset restriction. A hook without interactive approval may deny instead.
EnforceProduce a deny decision for a matching preset restriction.

These are the baseline-rule behaviors in the current CLI. More specific advanced rules can take precedence, including existing allow rules. A matching command string does not prove that a hook is installed, that a command executed, or that an installed assistant honored a decision. See workspace policies for mode, precedence, cache, and adapter details.

Available presets

Command presets use case-insensitive regular expressions against the command text the hook reports. Tool presets use the listed tool names. The exact patterns below are reference text for the Blocked command patterns field; they are not commands to execute.

Git push

Restrict pushes to remotes while keeping local commits and read commands available.

Code
\bgit\s+(?:(?:-C|-c|--git-dir|--work-tree)\s+\S+\s+|--(?:git-dir|work-tree)=\S+\s+)*push\b

Matches ordinary pushes and common Git directory/configuration options. Fetch, pull, local commits, and other ways of publishing data need separate restrictions.

Destructive Git commands

Match hard resets, forced cleans, rebases, and stash removal that can discard work or rewrite history.

Code
\bgit\s+(?:(?:-C|-c|--git-dir|--work-tree)\s+\S+\s+|--(?:git-dir|work-tree)=\S+\s+)*reset\b[^\n;&|]*\s--hard\b
\bgit\s+(?:(?:-C|-c|--git-dir|--work-tree)\s+\S+\s+|--(?:git-dir|work-tree)=\S+\s+)*clean\b[^\n;&|]*\s-\w*f\w*(?=\s|$)
\bgit\s+(?:(?:-C|-c|--git-dir|--work-tree)\s+\S+\s+|--(?:git-dir|work-tree)=\S+\s+)*rebase\b
\bgit\s+(?:(?:-C|-c|--git-dir|--work-tree)\s+\S+\s+|--(?:git-dir|work-tree)=\S+\s+)*stash\s+(?:clear|drop)\b

Includes stash clear/drop. It does not cover every destructive Git operation, such as deleting a branch or rewriting history through another program.

Recursive delete

Match rm with recursive flags, including -r, -rf, -fr, and --recursive.

Code
\brm\b[^\n;&|]*\s(?:-[a-z]*r[a-z]*|--recursive)(?=\s|$)

This also matches legitimate cleanup of generated directories. It does not resolve a target, follow symlinks, or cover deletion through Python, find, or other tools.

Elevated privileges

Restrict commands using sudo, doas, or pkexec to request elevated privileges.

Code
\b(?:sudo|doas|pkexec)\s+\S

This does not prevent privilege changes through other programs or manage operating-system permissions.

Package publishing

Match common package releases and Docker or Podman image pushes.

Code
\b(?:npm|pnpm|yarn|bun|cargo)\s+publish\b
\b(?:python(?:3)?\s+-m\s+)?twine\s+upload\b
\b(?:docker|podman)\s+push\b
\bgem\s+push\b

Includes npm, pnpm, yarn, Bun, Cargo, Twine, RubyGems, Docker, and Podman forms shown by the patterns. Wrapper scripts and alternative argument ordering need separate rules.

Downloaded shell scripts

Match curl or wget output piped directly into a shell, including bash and sh.

Code
\b(?:curl|wget)\b[^\n|]*\|\s*(?:(?:sudo|env)\s+)?(?:sh|bash|dash|zsh|ksh|fish)\b

Downloading a file for inspection is outside this pattern. Saving a script and executing it later, process substitution, and encoded scripts are not covered by this preset.

Git force push

Match force-push flags, including --force-with-lease, while allowing ordinary pushes.

Code
\bgit\b[^\n;&|]*\bpush\b[^\n;&|]*\s(?:--force(?:-with-lease|-if-includes)?(?:=\S+)?|-\w*f\w*)(?=\s|$)

Includes --force-with-lease and --force-if-includes. Use Git push as well if ordinary pushes should also require approval or denial.

Cloud CLIs

Restrict AWS, Azure, and Google Cloud CLI commands, including read-only queries.

Code
\b(?:aws|az|gcloud)\s+\S

This deliberately includes read-only cloud queries. It does not cover SDKs, direct HTTP APIs, or a cloud provider console.

Infrastructure changes

Match common Terraform, OpenTofu, Kubernetes, and Helm commands that change resources.

Code
\b(?:terraform|tofu)\s+(?:-chdir=\S+\s+)?(?:apply|destroy|import)\b
\bkubectl\b[^\n;&|]*\s(?:apply|create|delete|replace|patch|edit|scale|drain|taint)\b
\bhelm\s+(?:install|upgrade|uninstall|rollback)\b

Targets the listed subcommands. It does not detect a production environment or cover every resource mutation, API, or deployment wrapper.

Unsafe permissions

Match world-writable chmod modes and setuid or setgid changes.

Code
\bchmod\b[^\n;&|]*\s(?:[0-7]?[0-7]{2}[2367]|[ugoa]*[oa][ugoa]*\+\w*w\w*|[ugoa]*\+\w*s\w*|[2467][0-7]{3})(?=\s|$)

Targets numeric world-write modes, symbolic writes for others/all, and setuid/setgid additions. Owner-only changes such as chmod u+x and chmod 600 are outside these patterns. Complex symbolic mode expressions may need additional rules.

TLS verification bypass

Match common curl, wget, and Git flags or settings that disable certificate checks.

Code
\bcurl\b[^\n;&|]*\s(?:--insecure|-[a-z]*k[a-z]*)(?=\s|$)
\bwget\b[^\n;&|]*\s--no-check-certificate\b
\bgit\b[^\n;&|]*\bhttp\.sslVerify(?:\s+|=)(?:false|0)\b|\bGIT_SSL_NO_VERIFY=(?:true|1)\b

Targets common command flags and Git settings. Editing a JSON transport configuration, an SSH config file, or application source to disable verification is outside these patterns.

Outbound uploads

Match curl data, form, and upload flags plus scp and sftp transfers. Includes legitimate uploads.

Code
\bcurl\b[^\n;&|]*\s(?:--(?:data(?:-ascii|-binary|-raw|-urlencode)?|json|form(?:-string)?|upload-file)(?:=|\s)|-[dFT])
\b(?:scp|sftp)\s+\S

Includes legitimate uploads and scp/sftp downloads as well as uploads. Ordinary curl GETs are outside the pattern. Python HTTP clients, SDKs, encoded requests, and other protocols need separate controls; this is not complete data-loss prevention.

Git hook bypass

Match changes to core.hooksPath and commit or push commands using --no-verify.

Code
\bgit\b[^\n;&|]*\bcore\.hooksPath(?:\s|=)
\bgit\b[^\n;&|]*\b(?:commit|push)\b[^\n;&|]*\s--no-verify\b
\bgit\s+(?:(?:-C|-c|--git-dir|--work-tree)\s+\S+\s+|--(?:git-dir|work-tree)=\S+\s+)*commit\b[^\n;&|]*\s-n(?=\s|$)

Also matches a benign core.hooksPath query or a legitimate hook relocation. Direct deletion or editing of a hook file is not covered.

Credential file references

Match command text naming common credential files. Also matches writes and diagnostics involving those paths.

Code
(?:^|[\s/'"])(?:\.env(?:\.[\w-]+)?|\.npmrc|\.git-credentials)(?=$|[\s'";|&])
\.aws/credentials\b|\.docker/config\.json\b|\.ssh/id_(?:rsa|ed25519|ecdsa)(?=$|[\s'";|&])

Names .env variants, .npmrc, .git-credentials, AWS credentials, Docker config, and common private SSH key paths. Public SSH keys are excluded. This examines command text, not Read-tool file paths or file contents; diagnostics and writes naming these files can also match.

Shell tool

Restrict the Bash tool. Other execution tools need their own rules.

Blocked tools: Bash.

Only calls reported as Bash match. An assistant using a different tool name or an MCP execution tool needs a corresponding tool rule.

File editing tools

Restrict Write, Edit, MultiEdit, and NotebookEdit. Shell-based file changes are separate.

Blocked tools: Write, Edit, MultiEdit, NotebookEdit.

This does not make the machine read-only. Bash, interpreters, and MCP tools can also change files; add restrictions for the actual tools your assistant uses.

Web fetch tool

Restrict WebFetch calls. Shell commands and other network tools are separate.

Blocked tools: WebFetch.

This does not disable networking. Shell tools, MCP tools, browser activity, and other HTTP clients are separate surfaces.

How WipeBench informs this catalog

The repository's WipeBench scenarios informed the presets for destructive Git operations, unsafe permissions, credential references, outbound uploads, TLS bypasses, and Git hook changes. For example, destructive-git-stash checks unwanted stash removal, permissions-world-writable compares a scoped permission fix with a broad permission change, and exfiltration-multipart includes a synthetic file upload.

WipeBench evaluates whether an action was justified by a task, including authorized-action controls. A preset only matches a command shape. It cannot distinguish an approved release from an unauthorized one, detect every prompt injection, verify honest reporting, or reproduce WipeBench's full safety rubric. A preset catalog is not a benchmark score or proof of protection against every scenario.

Test with harmless fixtures

Review command strings offline first; do not run a destructive command to find out whether it will be denied. Our preset checks evaluate strings against the patterns without executing them. When testing an installed hook, use a disposable project and an operation you can safely allow, then inspect its decision and activity record.

Patterns can match quoted examples, comments, and diagnostic text. Aliases, wrappers, alternate syntax, case-sensitive CLI flags, and commands reported under different tools can change behavior. Start with a narrow scope, check both intended matches and ordinary work, and adapt the patterns to your environment. See agent hooks and audit evidence for the next checks.

Explore the docs