---
title: "Safety policy · intentic sandbox API"
description: "The document deciding when an agent stops to ask, and the record of what it decided. Every route in the safety policy group of the intentic sandbox API."
url: "https://intentic.dev/api/safety/"
---

Agent setup

# Safety policy

The document deciding when an agent stops to ask, and the record of what it decided

**On this page (3 sections)**

- [The safety policy this sandbox is judged against](#safety-policy)
- [Rewrite the safety policy](#safety-setPolicy)
- [Recent safety verdicts](#safety-log)

Settings next door are read by a parser; this one is read by a model. The policy is prose about which of the things an agent may already do are worth interrupting you about, and the two policy routes read and replace it whole. The third is the log every verdict lands in, including the ones nobody was interrupted for, and it is what makes the document writable: an owner can only author a rule for behaviour they can see.

**GET`/safety/policy` The safety policy this sandbox is judged against**

The document that decides when an agent stops to ask you before running something. Prose, not settings: it is read by the model that judges each command. When nobody has written one, this is the text the product ships with, and it describes the behaviour a fresh sandbox already has.

### What you send

Nothing. Call it as it is.

### What comes back

| Field | Type |
| --- | --- |
| `text` The policy, as the owner wrote… | string |
| `custom` False when nobody has edited it… | boolean |

Try it answered in this tab

curl

```bash
curl "$SANDBOX/safety/policy" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.safety.policy();
```

**POST`/safety/policy` Rewrite the safety policy**

Replaces the document whole. Nothing in it can widen what the sandbox is structurally allowed to do: it decides which of the things an agent may already do are worth interrupting you about.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `text` required The policy, as you want it… | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/safety/policy" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"text":"export const start = () => listen(PORT);\n"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.safety.setPolicy({
 "text": "export const start = () => listen(PORT);\n"
});
```

**GET`/safety/log` Recent safety verdicts**

What was judged lately, what the judge decided, and whether you were interrupted. Newest first. This is where you find out why you were not asked about something, which is the question a policy page otherwise cannot answer.

### What you send

Nothing. Call it as it is.

### What comes back

| Field | Type |
| --- | --- |
| `at` When it was judged, epoch milliseconds | integer |
| `program` The command or script, excerpted | string |
| `classes` The kinds of consequence triage matched,… | string[] |
| `decision` What the judge decided | "allow" | "ask" | "refuse" |
| `sentence` The judge's sentence | string |
| `outcome` What the gate did in the… | "allowed" | "asked" | "refused" |
| `answer` How the owner answered, when they… | "allowed" | "declined" | "unanswered" |
| `machine` Which connected device it was headed… | string |

Try it answered in this tab

curl

```bash
curl "$SANDBOX/safety/log" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.safety.log();
```

More in Agent setup

[Previous ← Settings](https://intentic.dev/api/settings/)[Next Privacy shield →](https://intentic.dev/api/privacy/)
