GPR-017 · high risk

Review browser automation tools

Require review before a named browser automation tool performs a supported action.

Decision

review

Matcher

tool = browser-automation

Reviewed

2026-08-09

Safe test cases

matching synthetic case

tool = browser-automationreview

different benign synthetic case

tool = benign-browser-automationunmatched

Limitations

  • Browser navigation, transfer, and privileged surfaces have separate policy dimensions.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: a4508cc3a520fbbd7e6ef65085daec63dd76a66bac1c881b5c0a57c75840a974

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.