Execution policies
The layered policy that controls leases, recovery, concurrency, agents, models, fallback, Git, verification, capabilities, approvals and the sandbox.
A policy is resolved by layering: platform defaults → organization → project → worker → task. Later layers override earlier ones; objects merge, arrays are replaced. Edit them under Settings → Organization execution policy, on the project page (Git policy, Advanced policy (JSON)), in the worker UI (Settings → Worker policy (JSON)), or per task.
Reference
| Key | Default | Meaning |
|---|---|---|
leaseMs / heartbeatMs | 5 min / 15 s | Task lease and renewal |
offlineThresholdMs | 60 s | When a worker counts as offline |
maxRestarts | 5 | Crash restarts before RECOVERY_REQUIRED |
maxRemediationAttempts | 3 | Verification fix rounds |
maxContextResets | 10 | Fresh sessions after context exhaustion |
hangTimeoutMs | 15 min | Silence before a hang is suspected |
maxExecutionMs | 0 (unlimited) | Cap on active execution time, excluding waits |
onWorkerLost | REQUEUE | Or RECOVERY_REQUIRED |
concurrency.* | 1 per project, 2 per worker | See Concurrency |
agents.preferred / allowed / blocked | any | Agent choice |
models.preferred, allowedProviders, blockedProviders, maxCostTier, optimizeFor | quality | Model choice |
fallback.chain | [WAIT] | See Recovery |
git.policy | COMMIT | NONE, COMMIT, COMMIT_AND_PUSH, PULL_REQUEST |
git.branchPrefix, git.workOnBranch | ao/, true | Task branches |
verification.enabled, steps, autoDetect | true, [], true | See Verification |
capabilities.installPolicy | ASK | ASK, AUTO, RESTRICTED |
capabilities.allowedTrust | Official, Verified, Local | Trust levels installed without approval |
capabilities.approvalRequiredPermissions | shell, secrets.read, browser.control, process.execute, git.write | |
capabilities.blockedPermissions | none | |
requireApprovalFor.production / push / plan | true / false / false | Approval gates |
sandbox.mode, network, writable, hidden | off, true | See Worker security |
Force push is never enabled implicitly.
Example
Organization policy
{
"concurrency": { "perOrganization": 10 },
"agents": { "preferred": ["claude-code"], "blocked": ["aider"] },
"git": { "policy": "PULL_REQUEST" },
"requireApprovalFor": { "push": true }
}