All documentation

Documentation Settings: Account

Governance: production, shipping and prompt guardrails

Every line in the Production & shipping and Prompt guardrails cards: what counts as production, what a push must pass, and rules on what people ask.

Production & shipping

The third card of part 3. It says what counts as production and what a push or publish must pass.

Where to find it. Mac: Settings → Account → Governance → 3 · Sharing, Review & Evidence. Web: Settings → Governance (part 3). iPhone: Settings → Governance → Rules → 3 of 3. Owner or admin edits.

PolicyDefaultWhat it doesWhen to turn it on
Production markersnoneHosts, URL patterns, variable names and account ids that mean production. A command or URL touching one asks or is refused.Always worth filling in.
What a production touch getsAskAsk, or Deny with the marker named.Deny when production changes go through a pipeline.
Opening a way in from the internetAsk every timeA tunnel, a server on every interface, or an opened firewall rule. Ask every time is never remembered. Deny refuses; Left to each member uses their switch.Deny on company laptops.
Every fetch honours the site's robots.txtoffA page closed to bots is not fetched. Off, each member's switch decides.When your legal team asks.
Personal data redacted from what the room fetchesoffEmails, phone and card numbers and national ids in fetched pages become placeholders before a seat reads them.When seats research customers.
Messaging channels off for membersoffA member's Telegram bot, Slack direct message or Discord bot cannot start or continue a team discussion.When work must start where the team can see it.
No phone preview of a local appoffA member cannot show their local app on a phone from their Mac.When the dev server holds real data.
Approvals on the Mac onlyoffQuestions a Mac asks are answered on that Mac; the phone, web and Slack only show them.When approvals need someone at the keyboard.
The ship check is a gate at push and publishoffPush and publish refuse while a finding stands. An admin waives one by id, which is audited.For repositories that deploy on push.
Checks in wordsnoneOne per line: warn or stop, a name, a colon, then a sentence judged against the change. Start as warn.When review keeps catching the same mistake.
Duplicated code before a pushEach member's Mac decidesOff for everyone, Pointed out, or Held by the gate. Six or more repeated lines count.When agents copy rather than reuse.
The team's own scannernoneA command run in the sandbox with the diff on its input; it prints SARIF and its findings show beside ours.When you already run a scanner in CI.
Licences a new dependency may carryno checkSPDX ids; an install with another licence asks first.When legal keeps an approved list.
Waived findingsnoneFinding ids an admin waived.Filled as you waive.
Public repositoriesAllowedWarn or Deny before a push or pull request to a public repository.Deny for closed-source teams.
Public repositories allowed anywaynoneFull names, one per line.For your open-source repositories.

Prompt guardrails

One line, Guardrails on what people ask, applied before a seat sees a message. One rule per line: log, warn or block, then credentials, customerData, "text" with a sentence, or "service" with your own https address, a Bedrock guardrail id or an Azure endpoint. Under block, a service that does not answer counts as a refusal. Start with log and watch before you block.

Settings → Account → Governance → Sharing, Review & Evidence on the Mac: the Production & shipping card
Settings → Account → Governance → Sharing, Review & Evidence on the Mac: the Production & shipping card

Further reading. OWASP Top 10 for LLM Applications 2025, OWASP GenAI Security Project.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.