Pages
Policy Config — Tool Allow-List

Source: c65 policy-definitions.md P5 — list-editor shape

‹ Policy Catalog

Tool Allow-List

Beta

Agents may only invoke tools on the approved list — the scope of what an agent's hands can touch.

Action & Autonomy
medium
P5
SatisfiesOWASP LLMOWASP ASICSF 2.0ISO 27001SOC 2
Underlying control— show
tool: allowlisted = falseedit as custom control →

Approved tools

5 entries · patterns supported (* and ?)

ToolScopeAdded byLast matched
Readbuiltinglobalseed1m ago
Writebuiltinglobalseed6m ago
Bashci agents onlyagentmark4m ago
WebSearchbuiltinglobalseed2h ago
github-mcp:*all tools on the approved serverglobaljess12m ago
you

Exceptions

Scoped carve-outs with a reason and an expiry — accepted risk, on the record.

ScopeValueReasonExpires
No exceptions — the policy applies everywhere.

Remediation shown on findings: Add the tool to the allow-list with a scope, or remove the agent's access to it.

Qpoint Brand Style Guide