Why central beats per-device
Per-device configuration drifts: each machine ends up with its own exceptions and nobody remembers why. A central policy is the baseline every device inherits, with exceptions that are explicit, dated and reviewed. It is the difference between managing a fleet and babysitting it.
What a baseline contains
- Tool allowlists: the shell commands and file paths every device may use.
- Secure mode defaults: read-only unless a device has a written reason not to be.
- Budgets: one daily cap and standard token budgets.
- Logging: everything to the shared audit trail, no exceptions.
Exceptions, the right way
- Write the exception as a dated ticket: what, which device, why, until when.
- Grant narrowly — one command, not a category.
- Review all active exceptions on a fixed day each month.
- Delete them when the date passes.
The compliance payoff
A central policy is also the answer to “show me your agent controls” — the same artifacts auditors ask for in audit compliance. One policy, one audit trail, one place where exceptions live: that is a control, not a collection of settings.