Playbook: Onboarding · Recommended Starting Policies · Threat Model · What Defaults Protect · Tool Policy Examples
1. Getting started (5 minutes)
1
Sign in
Go to your Unbound gateway at gateway.getunbound.ai — or your organization’s custom tenant domain, if you have one.
2
Connect your first tool
Open Configure, choose what to install, and run the command it builds. Tick Govern coding agent actions so Unbound enforces your policies on the tool’s commands and tool calls. Your existing Claude / OpenAI subscription keeps working as it does today.
3
Roll out to your team (admins)
Open Configure, set the scope to My org (MDM), and copy the install command it builds. It deploys Unbound to every user on a device with no per-user setup.
4
Load the starting policies
The last step of onboarding is Load Policies. Answer one question per category, keep the categories that match your risk, and confirm — that applies the 49-policy starting pack. Details in Recommended Starting Policies.
2. The dashboard — your home base
Your landing page is an at-a-glance health view of your whole org: devices and tools connected, agentic activity (terminal commands and MCP calls), how many actions were blocked / warned / allowed, total spend, and recommendations. Start here each day, then click into whatever needs attention.3. See what your AI tools are actually doing
Before you write a single policy, get visibility. Open AI Tools Discovery → Summary: it inventories every AI tool detected across your org and flags risk. Three things to check on day one:Shadow AI tools
Unsanctioned AI tools users installed on their own. Review the list and decide what’s approved.
Unconfigured Full-Auto users
Users running with auto-accept and no deny rules and sandboxing off — the highest-risk setups. The Permissions page shows exactly who.
Unverified MCP servers
MCP servers whose publisher is unofficial or unknown. Inventory → MCP Servers flags each one so you can spot shadow MCP.
4. Tool Policies — guardrails on what AI can do
Tool Policies govern the actions AI agents take — the terminal commands they run and the MCP tools they call — and stop the dangerous ones before they execute. Find them under Policies → Agentic Use, on the Tool Policies tab.What each action does
Warn is the one that varies by tool. It prompts for confirmation on Claude Code (run interactively), Copilot, Claude Cowork and Pi; on Cursor the command runs with no Unbound prompt; on Augment Code the prompt is left to Augment’s own tool-permission settings rather than to the policy; and it stops the command outright on Codex and OpenClaw.Where Claude Code runs headless — a script, CI, an SDK run — there is no prompt to show, so Warn allows the command through unless your organization has set the headless Warn action to Block. Treat Warn as a confirmation step, not a security boundary — where the action must actually be stopped, use Block or Require Slack Approval.
Three ways to create a policy
- Guided form (UI). Open Policies → Agentic Use and click Create Policy, then choose Terminal Commands or MCP Actions. Build the rule with dropdowns: When (command family) → If (field to match + pattern) → Then (action) → optionally scope to User Groups. A live preview shows the rule in plain English as you build it.
- Describe it in plain English. Click Ask AI on the policy list and type what you want — e.g. “Block any database command that drops or truncates” — and Unbound drafts the policy for you to review and edit before it’s created.
-
Ask your AI agent (CLI). Any user onboarded with the Unbound CLI can ask their agent (Claude Code, Cursor, Codex) to create the policy. The agent runs the
unboundCLI for you. Requires the CLI installed and logged in with an Admin role.The CLI previews what it will create and asks you to confirm. If you’d rather spell out every field yourself,--no-aiopts into the raw classification flags —--mcp-server,--mcp-action-type,--action,--custom-messageand the rest. See Tool Policy Examples.
Command families you can target (terminal commands)
Unbound classifies every command an agent runs into a family, grouped by area:
Each family matches on specific fields — e.g. Database Admin matches on database, table, operation, environment; Delete File matches on path. Run
unbound policy tool families to list every family with its fields, or pick one in the create dialog to see its options.
Examples and recommended policies
Recommended Starting Policies
The day-one pack, rule by rule — 49 policies in seven categories, each with a prompt you can paste into your AI agent to watch the policy fire.
Threat Model
The pack mapped to the threats it defends against — seven categories, what each blocks vs. audits, and the one-pager to take to your security review.
What Defaults Protect
What each default stops and what it leaves alone, in prose — and how to narrow a family rule down to one action.
Tool Policy Examples
Hand-picked terminal-command and MCP examples for the most common asks (block destructive DB ops, require approval before merge, audit every git push, …).
5. Where to find things
6. Settings you should know (admins)
Under Settings:- Integrations — connect Slack (required for the Require Slack Approval action).
- Policy Enforcement — choose what happens if Unbound is ever unreachable: Allow (operations run as usual — the default) or Block (operations are denied).
- Invite teammates and assign a role — Admin, Analytics Viewer (both can sign in) or Member (monitored, no console).
- Create User Groups to scope policies to specific teams. Groups carry no permissions of their own; they decide which policies reach someone, not what they may do in the dashboard.
7. Troubleshooting
- Policy not firing? Confirm it’s Active and scoped to the right user group (empty = everyone).
- MCP policy not matching? Check the exact MCP server name on AI Tools Discovery → Inventory → MCP Servers, or run
unbound policy tool mcp-servers. - Command classified differently than you expected? Open the command in Analytics → Agentic Use → Terminal Run — the family and risk score are shown on every entry. If no family expresses what you need, use the Custom family to match the raw command.
- “Require Slack Approval” not prompting? Connect Slack under Settings → Integrations.
Questions? Reach us in Slack or email support@unboundsecurity.ai.

