All documentation

Documentation Settings: Account

What Careful and Locked change

Line by line, what each Governance profile sets, and how to hold one project or every automation to a stricter profile.

The lines a profile sets

Choosing a profile writes these values over the team's policy. Lines not listed keep their value: rate limits, the spend ceiling, the privacy minimum and your own lists.

LineOpenCarefulLocked
Ask before git push after something was installedoffonon
Ask when a seat runs the same tool call three timesoffonon
No run until this policy has been fetchedoffonon
Require zero data retentionoffonon
Exclude providers that train on promptsoffonon
Members acknowledge this policyoffonon
Computer use toolsonaskask
Browser toolsononask
Delegation toolsononoff
New links expire afterNever30 daysNever, as links are off
Scan what is about to be sharedoffonon
RetentionUntil deleted365 days90 days
Public repositoriesAllowedWarnDeny
Guardrails on what people asknonelog credentials and customer datawarn on both
Refuse to run tools without the kernel sandboxoffoffon
Every discussion belongs to a team projectoffoffon
Members may add hooks of their ownononoff
Permission mode floorNoneNoneSmart
Only the team's allow rules spare a questionoffoffon
What a production touch getsAskAskDeny
Opening a way in from the internetAsk every timeAsk every timeDeny
Members may publish at a public linkononoff
Memories the room extracts wait for a personoffoffon
A reviewer from another provider must be in the roomoffoffon
Depth flooranyany1 reviewer, 1 round
The ship check is a gateoffoffon
Member Macs run only team accountsoffoffon
The warden seat watches every roomoffoffon
Members may mint API tokens and connect appsononoff
No product analytics for this teamoffoffon
Personal data redacted from what the room fetchesoffoffon
Messaging channels off for membersoffoffon
Approvals on the Mac onlyoffoffon
No phone preview of a local appoffoffon
Settings → Account → Governance on the Mac: the Run, Keep, Answer and Prove cards opened, each line with its Mac or Server chip
Settings → Account → Governance on the Mac: the Run, Keep, Answer and Prove cards opened, each line with its Mac or Server chip

A stricter profile for one project, or for automations

You can hold part of the team to Careful or Locked while the rest stays looser.

Where to find it. One project: web, Settings → Team → Access & Security → Project Access, the profile select beside the project. Every automation: Governance → Tools & Execution → Modes & permissions → Automations run under. Owner or admin.

What changes. The bound profile only tightens. For each line, the stricter of the team's value and the profile's wins; a project bound to Careful on a Locked team gains nothing. Off, the project or the automation follows the team's policy.

When to use it. A payments service on Locked while the docs site stays Open.

Further reading. NIST AI 600-1, Generative AI Profile, NIST, 2024.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.