01One policy: every toolA single declarative policy governs reads, writes, execution, network and environment across the whole tool surface, file tools resolve paths through it, and every execution path (run_command, run_script, monitor) shares one shell check. There is no side door for a tool that forgets to ask.
02Three profilesproject: read and write inside the project, the default for a normal repo. computer: read your home directory and work root, write only to the work root, state and temp. strict: network denied, shell refused until a kernel backend is active.
03Approval and confinement are orthogonalAuto-approval is not a permission escalation. --yolo skips the prompt but does not widen the sandbox: a command that violates policy is still refused, and the refusal is reported rather than silently retried.
04Environment sanitized by defaultChild processes inherit a sanitized environment: API keys, tokens and secrets are stripped before exec. Explicit passthrough is opt-in per variable, so a curious command cannot read the agent's provider key from its own process.
05Kernel backends where availablemacOS uses the system Seatbelt sandbox; Linux uses Landlock, gated by kernel ABI so older kernels get fewer guarantees, not silent ones. Windows reports an explicit refusal instead of running unconfined.
06Fail-closed capability reportingWhen a policy demands enforcement the OS cannot provide, the action is refused with the missing capability named, never downgraded quietly. Kernel enforcement itself is opt-in until the default allow-list passes a build fixture, so tool-layer policy is the shipped default.
07Backups before mutationFile tools take timestamped backups before destructive edits, independent of the sandbox. Sandboxing limits what is possible; backups limit what is costly.
08Published in the system promptThe active policy is written into the system prompt, so the model knows its own boundaries instead of discovering them through failures, fewer wasted rounds and fewer refusals to explain.