From 396faf86a7eb14c46f40ab83a5b879328a161bcc Mon Sep 17 00:00:00 2001 From: lakshya-dhariwal Date: Sun, 27 Sep 2026 19:33:30 +0530 Subject: [PATCH 1/2] docs(policies): note what changes when a policy is cloud-managed --- docs/policies/editor.mdx | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/policies/editor.mdx b/docs/policies/editor.mdx index 0363bee7c..41419d022 100644 --- a/docs/policies/editor.mdx +++ b/docs/policies/editor.mdx @@ -61,6 +61,13 @@ fp policies publish checkout-guard ./checkout.policy.mjs --description "Block fo `publish` parse-checks the source before sending it, so a syntax error surfaces here instead of on a machine at enforcement time. +### What changes when a policy is cloud-managed + +A published policy runs on every machine that pulls it, and two rules there differ from a local policy file (`.failproofai/policies/`): + +- **A cloud-managed policy is always hard.** `authority: "reviewable"`, `reviewedBy`, `userCanOverride` and `semanticPolicies.add()` are ignored. Publishing refuses a source that mentions these Jev-only names at all, and the check is a whole-word scan of the whole file - comments and strings included - so even a comment documenting this rule stops the publish. Keep the words out of a source you mean to publish. +- **Only the policy context is available.** The helpers a local setup may provide are not there; a cloud policy sees the [policy context](/reference/policy-sdk) (`eventType`, `toolName`, `toolInput`, `payload`, `session`, `cli`, `params`) and nothing else. + ## Write it yourself A policy is JavaScript or TypeScript against the `failproofai` API: From 3305fe1d395b23c24acb59b186c9556308b7e240 Mon Sep 17 00:00:00 2001 From: lakshya-dhariwal Date: Sun, 27 Sep 2026 19:42:58 +0530 Subject: [PATCH 2/2] docs(policies): authority comes from the deployment assignment, not the source --- docs/policies/editor.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/policies/editor.mdx b/docs/policies/editor.mdx index 41419d022..287593269 100644 --- a/docs/policies/editor.mdx +++ b/docs/policies/editor.mdx @@ -65,7 +65,7 @@ fp policies publish checkout-guard ./checkout.policy.mjs --description "Block fo A published policy runs on every machine that pulls it, and two rules there differ from a local policy file (`.failproofai/policies/`): -- **A cloud-managed policy is always hard.** `authority: "reviewable"`, `reviewedBy`, `userCanOverride` and `semanticPolicies.add()` are ignored. Publishing refuses a source that mentions these Jev-only names at all, and the check is a whole-word scan of the whole file - comments and strings included - so even a comment documenting this rule stops the publish. Keep the words out of a source you mean to publish. +- **Authority lives on the deployment, not in the source.** Source-level `authority: "reviewable"`, `reviewedBy`, `userCanOverride` and `semanticPolicies.add()` are ignored; a deployment assignment is what can make a published policy reviewable. Publishing refuses a source that mentions these Jev-only names at all, and the check is a whole-word scan of the whole file - comments and strings included - so even a comment documenting this rule stops the publish. Keep the words out of a source you mean to publish. - **Only the policy context is available.** The helpers a local setup may provide are not there; a cloud policy sees the [policy context](/reference/policy-sdk) (`eventType`, `toolName`, `toolInput`, `payload`, `session`, `cli`, `params`) and nothing else. ## Write it yourself