Skip to main content

One place for the rules

WHAWIT acts autonomously: agents investigate, the Coder writes fixes, MCP actions touch your infrastructure, incidents open and resolve themselves. Policies is the page where your organization decides how far that autonomy goes. Open Policies in the app sidebar (/policies). The page is organization-wide: the rules you set here apply to every project of the organization selected in the switcher.
The page is visible only to holders of the organization update capability — the Admin and Owner roles. Responders and viewers do not see the sidebar entry.
There is no save button. Each control persists the moment you change it and confirms with a Policies updated toast. Settings are independent — changing one never disturbs the others.

What lives here

Defaults are conservative

An organization that has never touched the page runs on defaults — no setup step is required, and nothing is applied retroactively when you change a policy later. Turning a policy off again is immediate and lossless.

Compliance criteria

Declare the frameworks that govern your data, toggle by toggle.

MCP Actions governance

Where the per-tool allow-list meets the organization-wide controls.