Network policy for where Cloud Agents may send traffic: an access mode (Allow all / Default + allowlist / Allowlist only) set per user or per saved environment, with Cursor's own services and SCM providers always reachable; Enterprise admins can lock it org-wide. A denylist with DNS filtering and an HTTP proxy has been described as planned, not shipped.