AI use policy template for coding agents

A one-page AI-use policy your team will actually follow. It sanctions the coding tools people already use (Claude Code, Cursor), sets a few clear rules for what an agent may and may not do, and requires a record. The difference that matters: some clauses are enforceable — a checkpoint blocks them before they run — and some stay advisory. This template marks which is which so the policy is honest about what technology enforces versus what people must uphold.

The template

Make the enforced clauses real

The "enforced" section only means something if a checkpoint actually blocks those actions. Scopebond's starter rules map to it directly. They record until you turn them on, so turn on each one your policy calls enforced:

npx @scopebond/hook@latest init                             # protected branches, destructive commands, secret files, signed records
npx @scopebond/hook@latest rules enforce protect-branches   # then block, rule by rule
npx @scopebond/hook@latest rules enforce safe-shell
npx @scopebond/hook@latest rules enforce protect-read
npx @scopebond/hook@latest rules enforce protect-write

On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.

What this does not do

A policy document does not enforce itself, and Scopebond does not judge whether your policy is complete or compliant. The enforced clauses are blocked by the checkpoint; the advisory clauses depend on people. Keep the two honestly separate — never present an advisory line as enforced.

Alternatives

FAQ

Is this legal advice?

No. It is a practical starting template to adapt; nothing here is legal advice. Have counsel review a policy before you rely on it.

How do I make a clause actually enforced?

Map it to a rule in a fail-closed checkpoint. Scopebond's starter rules cover protected branches, destructive commands and secret-file protection; they record until you turn each one on with rules enforce, then block.

Do you keep our code or prompts?

No. The record carries identifiers and fingerprints, never file contents or prompts, and secrets are scrubbed.

Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/conformance.test.mjs).