Skip to content
octic.ai

Managed policies, plus your own.

Octic-managed policies with enhanced protections apply out of the box, and your custom policies run alongside them. Together they evaluate every AI agent, MCP server, and coding agent, set each one’s trust state, and turn a violation into a finding with an owner.

Policies evaluating Acme Corp’s MCP servers

  • Every MCP server has an owner.

    mcp-servers-need-ownerCustom, Acme Corp

  • MCP servers with file or database access need a person’s review.

    sensor/mcp-data-accessOctic-managed, sensor pack

1 of 3 MCP servers is flagged and becomes a finding with an owner.

  1. mcp-jira

    Found via API

    Owner @platform

    mcp-servers-need-owner: Approve

    sensor/mcp-data-access: Pass

    Approved

  2. mcp-filesystem

    Found in network traffic

    Owner @platform

    mcp-servers-need-owner: Approve

    sensor/mcp-data-access: Review

    Unreviewed

  3. mcp-postgres-prod

    Found in network traffic

    Owner No owner

    mcp-servers-need-owner: Flag

    sensor/mcp-data-access: Review

    Flagged

    Rule
    mcp-servers-need-owner
    Reason
    No owner derived
    Finding
    MCP server with no owner
    Owned by
    Lena Okafor
    SLA
    14 days
    History
    Flagged, then assigned

On Acme Corp's map, each MCP server takes the trust state its verdicts add up to: mcp-jira approved, mcp-filesystem unreviewed, mcp-postgres-prod flagged. mcp-postgres-prod has a finding, mcp server with no owner, owned by Lena Okafor (@platform-leads).

Managed policies apply before you write a rule

Octic maintains managed policies, including enhanced protections, in one pack per source: your cloud, your code host, your model providers, Octic’s sensors, and more. Each pack is versioned, and you can turn off any rule in it.

Custom policies say what your organization allows: each one approves what it matches, or flags it. They run alongside the managed packs, and Octic evaluates every AI agent, MCP server, and coding agent against both.

Policies in effect
Octic-managed rules and Acme Corp's custom policy, evaluating a coding agent and two MCP servers.
  • Octic-managed rule sensor/corporate-accounts, in the sensor pack: Coding agents sign in with a corporate account.
  • Octic-managed rule sensor/mcp-data-access, in the sensor pack: MCP servers with file or database access need a person’s review.
  • Codex fails sensor/corporate-accounts: it is signed in with a personal account. Flagged.
  • mcp-filesystem waits for a review under sensor/mcp-data-access: it reads local files. Unreviewed.
  • Acme Corp's custom policy mcp-servers-need-owner runs alongside them: Every MCP server has an owner. mcp-postgres-prod has no owner, so the policy flags it. Flagged.

The managed rules decide Codex and mcp-filesystem. The custom policy is what makes mcp-postgres-prod flagged.

Start from a template, and see what a rule would flag

Build custom policies in the visual builder, starting from a template. The impact preview shows which AI agents, MCP servers, and coding agents the rule would approve or flag.

Each policy shows an example asset that triggers it and one that complies, as JSON, so you can check the rule does what you meant.

Example asset
Acme Corp's custom policy mcp-servers-need-owner in the visual builder, with an example asset and its impact preview.
  • Started from the template Require an owner: applies to MCP Server; requires an owner that is set; otherwise, flag.
  • Example asset that triggers the rule: mcp-postgres-prod, an MCP Server with owner null.
  • Example asset that complies: mcp-jira, an MCP Server with owner @platform.
  • Impact preview: the rule would flag 1 of 3 MCP servers.
  • mcp-jira: owner @platform. Approve.
  • mcp-filesystem: owner @platform. Approve.
  • mcp-postgres-prod: no owner. Flag.

A violation becomes a finding with an owner

When an AI agent, MCP server, or coding agent fails a policy, Octic sets its trust state and records the violation as a finding.

Every finding has an owner, an SLA, and a history, so each gap a policy finds lands with a person, a deadline, and a record of what happened to it.

What a violation sets off: mcp-postgres-prod is flagged by Acme Corp's owner policy and becomes a finding with an owner.
  • Acme Corp's custom policy mcp-servers-need-owner evaluates mcp-postgres-prod, which shadow-summarizer connects to.
  • mcp-postgres-prod has no owner, so the policy flags it. Flagged.
  • The violation becomes a finding: mcp server with no owner. Status open.
  • The finding is owned by Lena Okafor (@platform-leads).
On a violation

mcp-postgres-prod is flagged, and its finding is owned by Lena Okafor, who leads Platform.

Where this sits in Trust

The policy engine sets each trust state. The risk register gives you one risk view across your AI estate, including what your policies flag.

Back to Trust

Start with the managed packs, then add your own

Sign up and Octic-managed policies apply once your estate is on the map. Build a custom policy from a template, and see which AI agents and MCP servers it flags.

Or join the Design Partner Network.