GPR-009 · high risk

Review high-risk tool actions

Route a named high-risk tool action to human review before execution.

Decision

review

Matcher

tool = high-risk-action

Reviewed

2026-08-09

Safe test cases

matching synthetic case

tool = high-risk-actionreview

different benign synthetic case

tool = benign-high-risk-actionunmatched

Limitations

  • The matcher must be replaced with a real supported tool identifier before rollout.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: f947cc0863606b1bc2f83ce18a734dbf1a0ca7e2515f7292e7587e41650a7238

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.