Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions docs/policies/editor.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,13 @@ fp policies publish checkout-guard ./checkout.policy.mjs --description "Block fo

`publish` parse-checks the source before sending it, so a syntax error surfaces here instead of on a machine at enforcement time.

### What changes when a policy is cloud-managed

A published policy runs on every machine that pulls it, and two rules there differ from a local policy file (`.failproofai/policies/`):

- **Authority lives on the deployment, not in the source.** Source-level `authority: "reviewable"`, `reviewedBy`, `userCanOverride` and `semanticPolicies.add()` are ignored; a deployment assignment is what can make a published policy reviewable. Publishing refuses a source that mentions these Jev-only names at all, and the check is a whole-word scan of the whole file - comments and strings included - so even a comment documenting this rule stops the publish. Keep the words out of a source you mean to publish.
- **Only the policy context is available.** The helpers a local setup may provide are not there; a cloud policy sees the [policy context](/reference/policy-sdk) (`eventType`, `toolName`, `toolInput`, `payload`, `session`, `cli`, `params`) and nothing else.

Comment thread
coderabbitai[bot] marked this conversation as resolved.
## Write it yourself

A policy is JavaScript or TypeScript against the `failproofai` API:
Expand Down