Run safeguards
The first card of part 2, Tools & Execution. These lines decide what has to be true before a run starts and what stops one. Most are enforced by the member's Mac, since that is where commands run.
Where to find it. Mac: Settings → Account → Governance → 2 · Tools & Execution. Web: Settings → Governance (part 2). iPhone: Settings → Governance → Rules → 2 of 3. Owner or admin edits.
Where a member has their own number for the same thing, the team's acts as a ceiling: the lower of the two applies.
The policies, top to bottom
| Policy | Default | What it does | When to turn it on |
|---|---|---|---|
| No run until this policy has been fetched | off | The member's app fetches the team policy before each run and refuses until it has. Our servers refuse a managed call that carries an old version. A Mac that has never synced runs nothing. | When a policy change must reach everyone before the next run. |
| Ask before git push after something was installed this session | off | The Mac asks before a push that follows an install, even if the member turned that question off. | When supply-chain risk worries you more than one extra click. |
| Ask when a seat runs the same tool call three times in a row | off | A seat going in circles is stopped with a question before its fourth try. | When unattended runs burn money on loops. |
| Refuse to run tools without the kernel sandbox | off | Fail-secure: where no sandbox backs a run, such as Windows or a Swift workspace, commands and CLI seats are refused rather than run unboxed. It also locks every protection below. | When you cannot accept an unboxed command. |
| Sandbox protections members cannot switch off | none | Switch cards: Writes stay in the project, Home folder hidden, Network closed, Secret variables removed, MCP servers held in the sandbox too. Each stays on, on every member's Mac. | Pick the ones your security review insists on. |
| Stop after this many tool calls in a session | no limit | A count of tool calls after which the session stops. | When long unattended runs need a hard edge. |
| Hand over after N failed fixes in a row | the member's own (3) | An edit followed by a failing command is one attempt. At the limit the seat stops and a card shows the command, the tries and the output. 1 to 20. | When seats keep thrashing at a failing test. |
| Tasks one delegate call may start | the member's own (3) | How many separate discussions a lead may start at once, each in its own checkout, 1 to 6. | When parallel work runs up bills faster than you want. |
| Minimum app version | any | A Mac below it shows the update button instead of running. | After a release fixes a security issue. |
| The warden seat watches every room | off | A cheap model reads the ask and every tool call, and can only stop the run and say why. | When people run with loose permission modes. |

When not to use it. Refusing tools without the sandbox stops Windows members and Swift projects from running commands at all. Check who that affects first.
Further reading. The Protection of Information in Computer Systems, Saltzer and Schroeder, 1975. OWASP LLM06:2025 Excessive Agency, OWASP GenAI Security Project.