GPR-015 · high risk
Block production package installs
Provide a conservative starting point for blocking a reviewed production package-install target.
Decision
block
Matcher
package = production-package
Reviewed
2026-08-09
Safe test cases
matching synthetic case
package = production-package → block
different benign synthetic case
package = benign-production-package → unmatched
Limitations
- Environment scoping must be reviewed in Policy Studio before rollout.
Review before applying
This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.
Recipe SHA-256: 484dfb44598cfc8d37a5cd51f45eb784ae8611df74b8b3aac3575d06cf52e54c
When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.