Playbook: Onboarding · Recommended Starting Policies · Threat Model · What Defaults Protect · Tool Policy Examples
read, write or destructive. The tool picker lets you filter a server’s tools by type, so you can see which of them the rule will cover before you enable it.
Create these under Policies → Agentic Use → Tool Policies → Create Policy, then pick Terminal Commands or MCP Actions. Leave User Groups empty to apply org-wide, or scope to a team. The four actions are Audit, Warn, Block, and Require Slack Approval (the last needs the Slack integration).Warn behaves differently per agent: it prompts for confirmation on Claude Code (run interactively), Copilot, Claude Cowork and Pi; on Cursor the command runs with no Unbound prompt; on Augment Code the prompt is left to Augment’s own tool-permission settings; and it stops the command outright on Codex and OpenClaw. Where Claude Code runs headless, Warn allows the command through unless your organization has set the headless Warn action to Block. Where the action must actually be stopped, use Block.
Looking for the day-one set we recommend most teams enable first? See Recommended Starting Policies — 49 policies in seven categories, applied at the Load Policies step of onboarding. For the threat-modelling view of that pack, see Threat Model. For platform background, see the Onboarding Playbook.
How patterns are read
Every Pattern you type is read as exact, glob or regex, from the syntax you wrote:
Globs are anchored (
*prod* covers the whole value), regexes are an unanchored substring search, and both ignore case. If a pattern is ambiguous, force the reading with an exact:, glob: or regex: prefix.
Add more than one condition and they AND together — every one must match. Any tests your pattern against every field the family carries, so it stands alone. One value written several ways still matches: a host field matches on the bare host, and ~/.aws/credentials, .aws/credentials and the expanded absolute path all match each other. Every family and its fields are listed in Command family reference.
Terminal command examples
Block destructive database operations
Risk: an agent with DB credentials runsDROP DATABASE or TRUNCATE and wipes data irreversibly.
- When Command Family = Database Admin
- If Match Against = Operation, Pattern =
*DROP*(add a second rule for*TRUNCATE*) - Then Block
DROP DATABASE prod; is blocked. A normal SELECT is untouched.
TRUNCATE counts as Database Admin, not Database Write. A DELETE is a write, so that rule belongs on Database Write.Block production infrastructure teardown
Risk: an agent with cloud credentials deletes a live environment.- When Command Family = Cloud Destroy
- If Match Against = Environment, Pattern =
*prod* - Then Block
kubectl delete namespace production is blocked. Same for aws rds delete-db-instance --db-instance-identifier prod-db.
Require approval to tear down staging
Risk: staging teardown is sometimes legitimate, but you still want a human in the loop.- When Command Family = Cloud Destroy
- If Match Against = Environment, Pattern =
*staging* - Then Require Slack Approval
aws rds delete-db-instance --db-instance-identifier staging-db is held, and an approver gets a Slack DM to Allow or Deny. (A namespace deletion is not a good test here: the recommended pack blocks it in every environment, and Block wins over approval.)
Audit every git push
Risk: agents push code — including pushes that overwrite shared history. Log them all so you can see what your agents ship.- When Command Family = Git Action
- If Match Against = Operation, Pattern =
push - Then Audit
git push origin feature-x runs as usual and is logged in Analytics → Agentic Use → Terminal Run. Plain and force pushes are both operation push, so this one rule logs both — and singling out a force push needs the Custom family, below. A push to main is a poor test with the recommended pack loaded, because the pack blocks it.
Audit every file deletion
Risk: you don’t yet know what your agents delete — get visibility before you enforce.- When Command Family = Delete File
- If Match Against = Path, Pattern =
* - Then Audit
rm -rf build/ runs as usual, with a log entry in Analytics → Agentic Use → Terminal Run. Tighten the path later (e.g. */prod/*) and switch to Block.
Block a command by its raw text (Custom family)
Risk: the action you care about isn’t expressed by any field on any family — an interactive root shell, a house-specific release script, a particular flag. The Custom family is the escape hatch. It matches one pattern against the whole raw command, for every command an agent runs, whatever family it falls into. Its single field is alwayscommand.
It is also the family that holds when nothing else does: a command Unbound cannot place in a family is allowed, and only a Custom rule still fires on it. Custom covers an agent’s own file tools too — a native read, write, edit or delete matches as its shell equivalent (cat <path>, echo "..." > <path>, rm <path>).
- When Command Family = Custom
- If Pattern =
*sudo su* - Then Block
sudo su - is blocked, even though the recommended pack only audits privilege escalation.
This is the same approach the recommended pack uses to block git force push. A force push and a plain push are both operation
push, so no Git Action field can separate them — only the raw command text carries --force.MCP tool examples
Block destructive GitHub actions
Risk: an agent destroys something in a repo through the GitHub MCP, with no terminal command involved.- MCP Server = GitHub, Action type = destructive
- Then Block
Require approval before merging a PR (GitHub)
Risk: an agent self-merges a pull request with no human review.- MCP Server = GitHub, Tool =
merge_pull_request - Then Require Slack Approval
Block posting to Slack
Risk: an agent posts to channels — noise at best, data exfiltration at worst.- MCP Server = Slack, Tool =
slack_send_message - Then Block
Warn before editing Notion docs
Risk: an agent edits shared team documentation.- MCP Server = Notion, Tool =
notion-update-page - Then Warn (prompts on Claude Code, Copilot, Cowork and Pi; runs with no Unbound prompt on Cursor; left to Augment Code’s own tool permissions; stops the call on Codex and OpenClaw)
Audit all destructive Linear actions
Risk: you want a record of every deletion an agent makes in Linear.- MCP Server = Linear, Action type = destructive
- Then Audit
Creating these from the CLI
Every example above can be authored with theunbound CLI. Both creation commands require you to pick a lane: --prompt for AI-assisted creation, or --no-ai to pass raw classification flags yourself.
--custom-message is required whenever --action is BLOCK or WARN — it’s the text the agent itself reads back when the policy fires. When an agent is driving the CLI, use --prompt: --no-ai is refused inside a Claude Code session, and the error names the environment variable an interactive human can set to override it.unbound policy tool families lists every command family and the fields it accepts, and unbound policy tool mcp-servers lists the known MCP servers and the tools each one exposes. --command-family wants a family such as cloud_provision or delete_file — not one of the dashboard’s group headings like Filesystem or Cloud, which are not families.
