AI use policy template for coding agents
A one-page AI-use policy your team will actually follow. It sanctions the coding tools people already use (Claude Code, Cursor), sets a few clear rules for what an agent may and may not do, and requires a record. The difference that matters: some clauses are enforceable — a checkpoint blocks them before they run — and some stay advisory. This template marks which is which so the policy is honest about what technology enforces versus what people must uphold.
The template
- Scope. Applies to AI coding agents (Claude Code, Cursor, Copilot, Codex, MCP tools) used for company work.
- Approved tools. List the tools you sanction; using an unlisted tool for company code is not permitted (see shadow AI).
- Enforced by a checkpoint. No force-push to protected branches; no destructive commands (
rm -rf, disk/format); no reads of secret files (.env, keys) or writes to CI config. These are blocked before they run. - Advisory (people uphold). Review agent-generated code before merge; do not paste production secrets into prompts; use agents on non-production systems first.
- Records. Every agent decision is recorded in a tamper-evident, signed log that anyone can verify; records carry no file contents or prompts.
- Incident response. If an agent does something it shouldn't, follow the incident steps.
Make the enforced clauses real
The "enforced" section only means something if a checkpoint actually blocks those actions. Scopebond's starter rules map to it directly. They record until you turn them on, so turn on each one your policy calls enforced:
npx @scopebond/hook@latest init # protected branches, destructive commands, secret files, signed records
npx @scopebond/hook@latest rules enforce protect-branches # then block, rule by rule
npx @scopebond/hook@latest rules enforce safe-shell
npx @scopebond/hook@latest rules enforce protect-read
npx @scopebond/hook@latest rules enforce protect-write
On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.
What this does not do
A policy document does not enforce itself, and Scopebond does not judge whether your policy is complete or compliant. The enforced clauses are blocked by the checkpoint; the advisory clauses depend on people. Keep the two honestly separate — never present an advisory line as enforced.
Alternatives
- A generic acceptable-use policy — fine as prose, but its AI-tool clauses stay advisory unless something enforces them.
- Vendor-native controls — Claude Code and Cursor have their own settings; pair them with a fail-closed checkpoint and a record.
FAQ
Is this legal advice?
No. It is a practical starting template to adapt; nothing here is legal advice. Have counsel review a policy before you rely on it.
How do I make a clause actually enforced?
Map it to a rule in a fail-closed checkpoint. Scopebond's starter rules cover protected branches, destructive commands and secret-file protection; they record until you turn each one on with rules enforce, then block.
Do you keep our code or prompts?
No. The record carries identifiers and fingerprints, never file contents or prompts, and secrets are scrubbed.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/conformance.test.mjs).