Skip to content

Security Model

  1. Docker Container: Claude Code runs isolated from host
  2. Network Policy: Control container network access
  3. Plugin Governance: Only approved plugins execute
  4. Git Protection: Safety net blocks destructive commands
SourceTrust LevelCan Override
OrganizationAbsoluteNothing
TeamDelegatedWithin org bounds
ProjectRestrictedWithin team bounds
UserNoneExceptions only

Patterns in security.blocked_* are absolute:

  • Cannot be overridden by teams
  • Cannot be overridden by projects
  • Cannot be overridden by exceptions

Time-bounded overrides for governance controls. See Exceptions.