Skip to main content

List of Agentic Security Policies

Overview

Swif's Agentic Security policies control and monitor AI agents, such as Claude Code, Codex CLI, Cursor, and OpenClaw, on managed macOS, Windows, and Linux devices. Use this page to find the right policy, check what it requires, and open its full article.

Before you start

  • Install the Swif Agentic Security agent first. These policies configure the agent; they don't install it. See Getting Started with Swif's Agentic Security for Enterprise.

  • Install OpenClaw for the OpenClaw policies. The three OpenClaw policies need the OpenClaw gateway on the device.

  • Open each AI agent at least once. Some policies, such as Destructive Command Guard, need the agent's local files to exist on the device.

  • Create policies under Agentic Security. In the Swif Admin Console, go to Agentic Security > Policies and select Create new policy.


Available policies

Monitoring

Policy

What it does

Platforms

Device ownership

Learn more

Swif Agentic Security Logging Policy

Turns audit logging for supported AI-agent activity on or off. Logged actions appear in the device's Agentic Security view, rated Safe, Risky, or Danger.

macOS, Windows, Linux

Company-owned, BYOD

Swif ADR Sensor Policy

Collects activity from AI coding agents' local logs using Uber's open-source ADR Sensor, and can upload it to Swif. Supports Claude Code, Codex CLI, Claude Desktop, Cline, Cursor, and Warp.

macOS, Windows, Linux (Claude Desktop and Warp: macOS and Windows only)

Company-owned, BYOD

Blocking

Policy

What it does

Platforms

Device ownership

Learn more

Swif Destructive Command Guard (DCG) Policy

Blocks destructive commands, such as rm -rf and git reset --hard, before Claude Code, Codex CLI, or Cursor runs them. Supports an allowlist, and the agents can't turn it off themselves.

macOS (Apple silicon and Intel), Windows 11 (x64), Linux (Ubuntu 22.04+, Debian 12, Rocky Linux/RHEL 9)

Not stated

OpenClaw controls

Policy

What it does

Platforms

Device ownership

Learn more

Swif OpenClaw Tools Access Policy

Controls which tools OpenClaw agents can use: a base tool profile, allowed and denied tools, rules by provider and sender, sandbox rules, elevated commands, agent-to-agent access, and which sessions an agent can see.

macOS, Windows, Linux

Company-owned, BYOD

Swif OpenClaw Tools Runtime Policy

Controls how permitted tools run: command timeouts and background behavior, the apply_patch file-editing tool, loop detection, and limits on files passed to spawned sessions.

macOS, Windows, Linux

Company-owned, BYOD

Swif OpenClaw Tools Experimental Policy

Turns OpenClaw's multi-step planning tool on or off. Off by default. Newer OpenClaw versions changed how this feature is configured, so test it with your OpenClaw version.

macOS, Windows, Linux

Company-owned, BYOD


How the policies fit together

Monitoring policies record what agents do. Blocking and OpenClaw policies limit what they can do. Use both for complete coverage.

Goal

Use

See what AI agents did on a device

Logging Policy, ADR Sensor Policy

Stop agents from deleting files or Git history

Destructive Command Guard Policy

Limit which tools an OpenClaw agent can use

OpenClaw Tools Access Policy

Limit how long OpenClaw commands run, or restrict file editing

OpenClaw Tools Runtime Policy

Turn OpenClaw's planning feature on or off

OpenClaw Tools Experimental Policy

A few things to keep in mind:

  • Monitoring doesn't block anything. The Logging and ADR Sensor policies record activity but don't stop a risky action.

  • Access rules take priority in OpenClaw. The Runtime and Experimental policies can't make a tool available if the Tools Access Policy denies it.

  • Assign one policy of each type per device. If two policies of the same type conflict, the result can depend on which was applied last.

  • Removing a policy may not undo its settings. For the OpenClaw policies, deploy the settings you want to keep, confirm them, and only then remove the assignment.


Privacy

The Logging and ADR Sensor policies can collect prompts, responses, commands, file paths, and tool results. Before you turn them on, especially on BYOD devices:

  • Tell users what's collected.

  • Limit who in your organization can view the data.

  • Set retention rules for it.

Each policy's article has more detail.


How to use this list

  1. Find the policy you need in the tables above.

  2. Check the platforms and requirements. Devices that don't meet them don't apply the policy.

  3. Open the article for settings, examples, verification steps, and troubleshooting.

  4. Test on a small pilot group before a wider rollout.


Related resources

Did this answer your question?