Toolkit
Settings & Policy · Compositions
On this page6 sections
Compositions
Settings + Project Instructions
Settings enforce available capabilities; instructions explain intended use and remediation. Generate both from one operating policy where practical.
Settings + Sandbox
Use product permissions for usable workflow and OS, container, or hosted isolation for containment. Test the boundary rather than trusting a mode name.
Settings + Hooks
Settings activate and constrain hooks; hooks provide lifecycle checks. Keep a protected external gate for consequential outcomes.
Settings + MCP Policy
Client settings decide which servers and tools are visible. Server-side identity and authorization decide what those tools can actually do.
Settings + Subagents
Define whether child agents inherit, narrow, or override parent tools and approvals. Least privilege should become stricter with specialization, not broader.
Settings + Release Authorization
The AgentA worker you delegate to: brief it, and it takes steps on its own. A chatbot answers; an agent acts.An LLM that runs tools in a loop toward a goal — it acts, checks the result, decides the next step, and repeats until done.Full definition may prepare and verify a change. A deterministic policy layer evaluates admissible evidence and a named human authorizes release when required.
Source register
Settings & Policy sources
Primary vendor documentation reviewed on the date shown. Links may change after publication.
- Claude Code settings (opens in a new tab)
Anthropic · official docs · accessed 2026-08-01
- Codex config basics (opens in a new tab)
OpenAI · official docs · accessed 2026-08-01
- Overview of customizing GitHub Copilot CLI (opens in a new tab)
GitHub · official docs · accessed 2026-08-01
- GitHub Copilot CLI command reference (opens in a new tab)
GitHub · official docs · accessed 2026-08-01