Access controls
Table of contents
Access controls are expressed as policies. Local and organization pages describe where policies apply. Network and filesystem pages describe the rules inside those policies. MCP policies use Cedar statements instead of the network and filesystem rule format.
Policy scope
- Local policy: configure network rules on a developer machine with
the
sbx policyCLI. - Organization policies: manage centralized policies for an organization or team.
Access surfaces
- Network access policies: control outbound network access from sandboxes.
- Filesystem access policies: control which host paths sandboxes can mount as workspaces.
- MCP access policies: control MCP server registration, tool calls, resources, prompts, and approval gates with Cedar policy.