1 min lesson
Practice Enterprise controls
Practice Enterprise controls on one real case. Check the result before moving on.
Step 1 of 3
Work through one real case until you can sort each governance control into steer-only or enforcing and name the mechanism that enforces a risky operation. Check whether run modes and hooks block the risky operation, and an audit hook logs the attempt. Confirm model and MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. access match policy, and Auto offers only the optimization modes policy allows. Make sure repo and Git scopes are protected, and browser and terminal controls are set too. Avoid treating model instructions as hard policy. Keep the evidence with the result. For Auto routing, verify the allowed optimization modes separately: all are available by default, and admins can disable up to two.
Learn more
Full explanation
Admin control plane
rm -rf on a developer's machine. The tempting fix is a rule that says 'don't.' I sort the available controls into what steers and what actually enforces before I pick.never run rm -rf or other destructive shell commandsbeforeShellExecution from the dashboard that blocks the command outright, with an audit hook on the same event that logs the attempt.