Skip to lesson
Exit
Model, MCP, integration and safety controls1 / 3

1 min lesson

Practice Enterprise controls

Practice Enterprise controls on one real case. Check the result before moving on.

Step 1 of 3

Work through one real case until you can sort each governance control into steer-only or enforcing and name the mechanism that enforces a risky operation. Check whether run modes and hooks block the risky operation, and an audit hook logs the attempt. Confirm model and MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. access match policy, and Auto offers only the optimization modes policy allows. Make sure repo and Git scopes are protected, and browser and terminal controls are set too. Avoid treating model instructions as hard policy. Keep the evidence with the result. For Auto routing, verify the allowed optimization modes separately: all are available by default, and admins can disable up to two.

Learn more

Full explanation

Admin control plane

Enterprise controls, stop agents running destructive terminal commands
Admin control plane
SayPlatform security wants one thing: agents must never run a destructive shell command like rm -rf on a developer's machine. The tempting fix is a rule that says 'don't.' I sort the available controls into what steers and what actually enforces before I pick.
SayA Team Rule or an AGENTS.md line like this steers the model. It is guidance, and the model can still ignore it or work around it.
Typenever run rm -rf or other destructive shell commands
SeeUseful as a baseline, but non-deterministic. On its own it does not stop the command.
DoAdd the deterministic layer. Set the org Run Mode policy to Auto-review instead of Run Everything, so shell commands are sandboxed where Cursor can and the rest go through the allow-or-block classifier. Then distribute a team hook on beforeShellExecution from the dashboard that blocks the command outright, with an audit hook on the same event that logs the attempt.
SeeNow the boundary is enforced by the sandbox and the hook, not requested by a rule. The rule still steers; the Run Mode policy and the hook enforce.
DoAudit that the control changed behavior: try a destructive command in a test repo and read the audit hook's log.
SeeThe command is blocked and logged. If it had still run, the rule was carrying weight it can't hold and the enforcement layer was missing.
SeeA deterministic control stops the risky operation. The rule is named as steering only, and the audit shows that behavior changed. Model instructions were never treated as hard policy.