What are Tool Policies?
Tool Policies allow you to monitor and control actions taken by AI coding tools in your organization. Create policies to track, warn on, or block terminal commands executed by AI agents or MCP tool calls made through integrated servers like GitHub, Linear, Sentry, and more. Gateway URL: https://gateway.getunbound.ai/policies/tool-policiesPolicy Types
When you click Create Policy, you’ll be asked to choose what you want to monitor:Terminal Commands
Monitor shell commands executed by AI coding tools like Claude Code, Cursor, Roo Code, and Cline.- Select a Command Family (e.g.,
delete_file,git_action,remote_access) - Set Match Against to the command field you want to inspect (e.g.,
path,branch, orAny) - Define a Pattern to match specific paths, branches, or operations
- Supports exact match, glob patterns (
/etc/*), and regex (.*\.env$)
MCP Actions
Monitor tool calls made through MCP (Model Context Protocol) servers.- Select an MCP Server (e.g., GitHub, Linear, Sentry)
- Select the MCP Tool to monitor (e.g.,
create_pull_request,create_issue)
read, write, or destructive. Action type is available for targeting through the policy API; the create-policy modal itself targets a specific MCP server (or canonical group) and its tools.
Canonical groups offer broader targeting: in the modal, pick an MCP Service — a logical service group (e.g., “code repository writes”) — to apply a policy to all matching tools across any connected MCP server, without naming individual servers or tools.
If you are building an MCP server that calls back into Unbound for policy checks, manage your MCP credentials from Connect → MCP Keys in the dashboard.
Actions
Each tool policy has an action that determines what happens when a match is found:| Action | Behavior |
|---|---|
| Block | Reject the command or tool call entirely. The action is prevented from executing. |
| Warn | Allow the action but flag it for review. Users receive a warning notification. |
| Audit | Silently log the action for monitoring. No user-facing impact. Available for reporting and analytics. |
| Require Slack Approval | Hold the command in a pending state and send an interactive Slack DM to the developer. The approver can Allow Once, Allow for 1 hour, or Deny. The agent retries automatically after a decision. Requires the Slack integration to be configured. |
Applying to Users
By default, a tool policy with no user groups applies to everyone in your organization. To restrict a policy to specific teams, assign it to one or more user groups during creation or editing.- No user groups selected — The policy applies organization-wide
- User groups selected — The policy applies only to members of those groups
- When a user group is modified, policy enforcement updates automatically for all affected users
Policy Coverage
The Policy Health view in the Tool Policies dashboard shows which command families and MCP tool categories have no active policies — coverage gaps where agent actions are completely unmonitored. Open the Policy Health tab, then switch between the Terminal and MCP sub-views to see coverage for each.Risk-score policies
Every terminal command match carries a per-match risk score derived from its classification. A Risk Score policy applies its action whenever a command’s score meets or exceeds a configuredrisk_score_threshold, independent of any specific command family.
risk_score_thresholdis an integer from 1–10.- A lower threshold fires the action on more command matches; a higher threshold reserves it for the highest-risk commands.
risk_score_threshold is returned in the policy API response.
Risk Score policies are currently API-only — they aren’t yet exposed in the create-policy modal.
Policy Recommendations
The dashboard proactively surfaces policy suggestions based on observed agent activity. Each recommendation identifies either a complete gap (no policy covers this command or tool type at all) or a partial gap (a policy exists but doesn’t match all observed variants). Recommendations appear automatically as your agents run. You can create the suggested policy directly from the recommendation card, or dismiss it.Quick Example
Let’s create a policy to audit when AI tools delete files in sensitive directories:- Go to Tool Policies and click Create Policy
- Select Terminal Commands
- Fill in the form:
- Name: “Audit Sensitive File Deletions”
- Command Family:
delete_file - Match Against:
path - Pattern:
/etc/*or*.env
- Set Action to
Audit - Optionally select User Groups to limit the policy to specific teams
- Click Preview Impact to see historical matches
- Click Create Policy
Tool Policies vs Security Policies
Tool policies and security policies serve different purposes and are managed independently:| Tool Policies | Security Policies | |
|---|---|---|
| Purpose | Control terminal commands and MCP tool calls | Protect sensitive data with guardrails, routing rules |
| Covers | Terminal command families, MCP server/tool actions | PII detection, secrets detection, regex patterns, ban lists, routing |
| User group scoping | Directly on the tool policy | Directly on the security policy |
| Actions | Block, Warn, Audit, Require Slack Approval | Block, Redact, Audit, Route |
Slack Integration
Set up Slack for interactive approval workflows
CLI Policy Management
Create and manage tool policies from the terminal
Tool Policy Hooks
Integrate policy checks directly into your agent or framework

