Skip to content

ai-gov: approval-required network access - #26059

Open
craig-osterhout wants to merge 1 commit into
docker:mainfrom
craig-osterhout:docs-sbx-ask-policy
Open

craig-osterhout wants to merge 1 commit into
docker:mainfrom
craig-osterhout:docs-sbx-ask-policy

Conversation

@craig-osterhout

@craig-osterhout craig-osterhout commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Description

Document approval-required network access. An organization network policy can
require a developer to confirm each destination before a sandbox reaches it.
Without organization governance, a request that matches no rule also asks for
approval.

Page What changed
network.md What approval is, what satisfies it, how overlapping policies behave, and the sbx policy approval workflow. Responding from the sbx tray app, and what approving grants for a request an HTTP rule matches
organization.md The Require approval before access setting, that the support message also appears on approval blocks, and that resetting local policy clears recorded approvals
concepts.md Approval as a policy-level setting and a third evaluation outcome. How network approval differs from MCP @requireApproval
local.md How the Balanced and Locked Down presets handle an unmatched request, what sbx policy check reports for it, and a troubleshooting entry for a request blocked pending approval
monitoring.md Filter for rules recorded from an approval

Related issues or tickets

ENGDOCS-3373

Reviews

  • Technical review
  • Editorial review
  • Product review

@netlify

netlify Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 2af8257
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6ab6f28884d68c00087c4b3c
😎 Deploy Preview https://deploy-preview-26059--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Comment thread content/manuals/ai/sandboxes/governance/access-controls/local.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md
@chrispatrick

Copy link
Copy Markdown
Contributor

This is currently behind a FF, so we will need to coordinate publication of the docs.

@craig-osterhout
craig-osterhout marked this pull request as ready for review September 21, 2026 18:54

@derekmisler derekmisler left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

left 3 questions, 3 suggestions, and 2 nitpicks inline. the approval-vs-denial contradictions between network.md, organization.md, and local.md are the ones to check first.

Comment thread content/manuals/ai/sandboxes/governance/access-controls/local.md
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/organization.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/concepts.md
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md Outdated
@craig-osterhout
craig-osterhout force-pushed the docs-sbx-ask-policy branch 3 times, most recently from ca73613 to befc141 Compare September 25, 2026 22:03
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants