One place for the rules
WHAWIT acts autonomously: agents investigate, the Coder writes fixes, MCP actions touch your infrastructure, incidents open and resolve themselves. Policies is the page where your organization decides how far that autonomy goes. Open Policies in the app sidebar (/policies). The page is organization-wide: the
rules you set here apply to every project of the organization selected in the switcher.
The page is visible only to holders of the organization update capability — the
Admin and Owner roles. Responders and viewers do not see the sidebar entry.
What lives here
Defaults are conservative
An organization that has never touched the page runs on defaults — no setup step is required, and nothing is applied retroactively when you change a policy later. Turning a policy off again is immediate and lossless.Related
Compliance criteria
Declare the frameworks that govern your data, toggle by toggle.
MCP Actions governance
Where the per-tool allow-list meets the organization-wide controls.

