Only the tools you approved fire. Everything else is denied at the pre-tool boundary with a reason the agent can read.
For: Teams running the Copilot CLI or cloud agent on real repositories
Blocks any tool call outside the approved software list for the engagement.
Escalates outbound calls to a host that is not on the allowed egress list.
Restrains writes outside the paths the engagement scope covers.
# Copilot Agent Tool Whitelist
# Fork: this is the ai_agency "Tool-Use Whitelist" gate, wired at the
# preToolUse boundary in .github/hooks/*.json.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: copilot-agent-tool-whitelist
surface: copilot
standards: [SOC2-CC7.2, ISO27001-A.8.9]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
approved_tools: [read, edit, search, run_tests, open_pull_request]
allowed_egress_hosts: ["api.github.com", "registry.npmjs.org"]
rules:
- name: approved_tool_enforcement
when: "always"
decision: |
BLOCK IF tool not in approved_tools
ALLOW OTHERWISE
reason_code: tool_not_on_approved_list
- name: network_egress_gate
when: "tool_call.egress_host != null"
decision: |
ESCALATE IF tool_call.egress_host not in allowed_egress_hosts
ALLOW OTHERWISE
reason_code: egress_host_not_allowed
- name: write_scope_containment
when: "tool in ['edit', 'write']"
decision: |
RESTRAIN IF not path.startswith(engagement.scope_root)
ALLOW OTHERWISE
reason_code: write_outside_engagement_scope
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.