Set rules for all your computers

Decide, rule by rule, what Scopebond stops before it happens and what it only records, for every agent at once, for one environment, or for one agent. Changes reach each connected computer within a few minutes of its next action. Only an owner or admin can change a rule; everyone in the workspace can see the settings.

What Block and Monitor mean

SettingWhat happens on the computerWhat you see in the workspace
BlockThe action is stopped before it runs, and the agent is told whyThe action, marked Blocked
MonitorThe action runsThe action, with the rule it matched

Always on: Scopebond's own protection. A coding agent can never change Scopebond's settings or your agents' hook settings, switch off the Scopebond Agent, or uninstall Scopebond, and nobody can relax this from the workspace.

Recorded only: some actions (for example, installing packages) are not yet reported separately by coding agents. They are recorded with the activity, but you cannot block them yet.

Every rule starts on Monitor: it records what it would have stopped and blocks nothing until you choose Block for it. Until you change a rule here, each computer keeps its own rules. From Scopebond 0.18 those also start on Monitor, until someone at that computer runs npx -y @scopebond/hook@latest rules enforce <rule>. Connecting a computer does not change what it blocks.

Change a rule

  1. Open Rules.
  2. Under Show settings for, choose All agents, one environment, one team or one agent.
  3. Tick the rules to change, then choose Block or Monitor.
  4. For Contact websites and online services, list the sites your agents need before you choose Block (for example api.github.com, *.npmjs.org). Everything else is stopped.
  5. For branches and programs you can add to each computer's own list. You cannot remove entries from it here.
  6. Select Review change. The preview says what changes, how many connected computers it reaches, which narrower settings stay, and how often the rule matched in the last seven days.
  7. Select Apply. If your workspace requires a second person for changes to Block, the button reads Ask for approval, and another owner, admin or reviewer approves it under Waiting for approval.

If someone else changed the rules while you were looking at a preview, you see the updated preview instead. Check it and apply again.

Exceptions

A setting for one agent beats a setting for its team, which beats a setting for its environment, which beats a setting for all agents. A team setting reaches the agents the team owns (set on the Agents page), including agents given to the team later. A rule shows N exceptions differ when narrower settings disagree with the one you are looking at.

  • A setting for an environment, team or agent is an exception: Scopebond asks Why is it needed?, who owns it, and whether it ends after 1, 7 or 30 days. When it ends, Scopebond removes it the same way a person would, and the wider setting applies again on each computer within a few minutes of its next activity.
  • Rules → Exceptions lists every exception with its reason, owner and end, those ending in the next 7 days, and those that ended in the last 30 days. An owner or admin can End now.
  • An exception that blocks Read passwords, keys or secrets or Change build and release settings can skip exact paths (a folder ends in /**), and one that blocks Push straight to a protected branch can skip exact branch names. A skip matches exactly, same case, and never covers Scopebond's own settings. Computers apply skips from Scopebond 0.11.0; until a computer is updated it keeps protecting those targets.
  • When you change a rule for all agents, an environment or a team, narrower settings are kept unless you tick Also replace different settings.
  • To remove an exception, choose that environment, team or agent under Show settings for and select Use the wider setting, or use End now on the Exceptions tab.

See whether each computer has your rules

The line above the rules says how many computers have applied the latest version. Show computers lists each one:

StateMeaningWhat to do
Uses its own rulesYou have not changed any rule for this computer's environmentNothing
AppliedThe computer confirmed it loaded exactly this versionNothing
ApplyingIt will pick up the change on its next actionNothing; it updates within a few minutes
Waiting for the computerIt has not been active for 15 minutesIt updates when it is next used
Needs a Scopebond updateIt is active but runs a Scopebond version that cannot receive rules from the workspaceOn that computer run npx -y @scopebond/hook@latest install
Could not applyThe computer refused the version, with the reason shownIts previous rules stay in force. Check the reason, then change the rule again

To check right away on a computer instead of waiting, run npx -y @scopebond/hook@latest policy sync there. npx -y @scopebond/hook@latest status shows which rules are in force and when they were last checked. In Windows PowerShell, type npx.cmd instead of npx if PowerShell says running scripts is disabled.

A computer follows workspace rules only once a setting reaches it: a setting for all agents, for its environment or for its own agent. A change made for one agent leaves the other computers in its environment on their own rules, and they keep reading Uses its own rules.

Undo a change

Open Recent changes under the rules and select Restore this version next to the version you want. This creates a new version with those settings, so the history stays complete. Exceptions for single agents stay as they are now.

On the computer

While the workspace sets the rules, editing them on that computer (scopebond rules …) is refused with a message pointing here. If you disconnect the computer, or remove every rule change for its environment, it goes back to its own rules. A computer is never left without rules.

Removing Scopebond from a computer

A coding agent cannot remove Scopebond: the hook refuses it. A person removes it from their own terminal, outside the agent, with npx -y @scopebond/hook@latest uninstall (in Windows PowerShell, npx.cmd).

Before they do, an owner or admin opens the computer's page under Agents → Computers and selects Allow removal (24 h), or disconnects the computer. Otherwise the workspace sends a critical Scopebond removed alert to its alert channels.