The lines a profile sets
Choosing a profile writes these values over the team's policy. Lines not listed keep their value: rate limits, the spend ceiling, the privacy minimum and your own lists.
| Line | Open | Careful | Locked |
|---|---|---|---|
| Ask before git push after something was installed | off | on | on |
| Ask when a seat runs the same tool call three times | off | on | on |
| No run until this policy has been fetched | off | on | on |
| Require zero data retention | off | on | on |
| Exclude providers that train on prompts | off | on | on |
| Members acknowledge this policy | off | on | on |
| Computer use tools | on | ask | ask |
| Browser tools | on | on | ask |
| Delegation tools | on | on | off |
| New links expire after | Never | 30 days | Never, as links are off |
| Scan what is about to be shared | off | on | on |
| Retention | Until deleted | 365 days | 90 days |
| Public repositories | Allowed | Warn | Deny |
| Guardrails on what people ask | none | log credentials and customer data | warn on both |
| Refuse to run tools without the kernel sandbox | off | off | on |
| Every discussion belongs to a team project | off | off | on |
| Members may add hooks of their own | on | on | off |
| Permission mode floor | None | None | Smart |
| Only the team's allow rules spare a question | off | off | on |
| What a production touch gets | Ask | Ask | Deny |
| Opening a way in from the internet | Ask every time | Ask every time | Deny |
| Members may publish at a public link | on | on | off |
| Memories the room extracts wait for a person | off | off | on |
| A reviewer from another provider must be in the room | off | off | on |
| Depth floor | any | any | 1 reviewer, 1 round |
| The ship check is a gate | off | off | on |
| Member Macs run only team accounts | off | off | on |
| The warden seat watches every room | off | off | on |
| Members may mint API tokens and connect apps | on | on | off |
| No product analytics for this team | off | off | on |
| Personal data redacted from what the room fetches | off | off | on |
| Messaging channels off for members | off | off | on |
| Approvals on the Mac only | off | off | on |
| No phone preview of a local app | off | off | on |

A stricter profile for one project, or for automations
You can hold part of the team to Careful or Locked while the rest stays looser.
Where to find it. One project: web, Settings → Team → Access & Security → Project Access, the profile select beside the project. Every automation: Governance → Tools & Execution → Modes & permissions → Automations run under. Owner or admin.
What changes. The bound profile only tightens. For each line, the stricter of the team's value and the profile's wins; a project bound to Careful on a Locked team gains nothing. Off, the project or the automation follows the team's policy.
When to use it. A payments service on Locked while the docs site stays Open.
Further reading. NIST AI 600-1, Generative AI Profile, NIST, 2024.