Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Policy schema

{
  "budget": 80,
  "scar_limit": 10,
  "rate_limit": { "max_actions": 30, "window_secs": 60 },
  "tools": {
    "<tool name>": { "cost": 1, "requires_approval": false, "max_calls": null }
  },
  "default_rule": null
}
FieldTypeRequiredDefaultMeaning
budgetinteger ≥ 0yesLifetime credits. Never refilled
scar_limitinteger ≥ 0yes(Policy::new: 10)Scar score at which the agent is terminated
toolsobjectyesTool name → tool rule. The allowlist
default_ruletool rule or nullnonullRule for unlisted tools. null denies them with a moderate scar
rate_limitobject or nullnonullSliding-window limit on allowed actions
rate_limit.max_actionsintegeryes, if setAllowed actions per window
rate_limit.window_secsintegeryes, if setWindow length in seconds

Tool rule

FieldTypeRequiredDefaultMeaning
costinteger ≥ 0yesMinimum charge per call
requires_approvalbooleannofalseHold each call for an operator
max_callsinteger or nullnonullLifetime cap on allowed calls

Scar weights: minor 1, moderate 3, severe 10, fatal terminates immediately.

The policy is stored as the log’s policy record and can’t change. Tool names are case-sensitive strings of 1–128 characters on the guard server.