GPR-020 · low risk

Allow a reviewed workflow

Allow a named routine workflow only after its actions have been reviewed and bounded.

Decision

allow

Matcher

tool = trusted-workflow

Reviewed

2026-08-09

Safe test cases

matching synthetic case

tool = trusted-workflowallow

different benign synthetic case

tool = benign-trusted-workflowunmatched

Limitations

  • Re-review the workflow when its tools, permissions, or external dependencies change.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: 699f8e4175829cb9f953e32a237a783cfcf776ff426e3f338d4771885e2701da

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.