Risk policies can target chosen MCP servers, gateways, and tools instead of everything
A risk policy no longer has to apply everywhere. The scope step gains a mode switch between Everywhere and Selected MCP servers, with a two-pane picker for the servers and their tools and a tool rule you can set per server. Policies written this way are restricted to tool traffic, which is what makes narrow targeting safe: an Inspect matrix replaces the old per-category rows, and in MCP mode the User and Assistant categories are unavailable rather than silently ignored. Organization admins can also turn the device agent's Shadow AI scan off from the fleet configuration, for fleets where that scan is not wanted.Features
- Scope a risk policy to selected servers and tools #6785 - The scope step offers Everywhere or Selected MCP servers, with a two-pane picker carrying an All MCP servers row, per-server tool lists, and a tool-rule popover over MCP annotation hints. An Inspect matrix covering User, Tool requests, Tool responses, and Assistant replaces the per-category scope rows, with CEL editing kept for Everywhere. In MCP mode, User and Assistant are unavailable, Tool responses is noted as applying once response scanning ships, and Block policies carry a latency note. Inline validation requires All MCP servers or at least one selection. (Author: @vishalg0wda)
- Turn off the device agent's Shadow AI scan #6703 - Organization admins can disable the device agent's Shadow AI scan from the fleet configuration. (Author: @AshGodfrey)
Bug fixes
- Scoped policies save without a tool list per server #6824 - Creating or updating a risk policy scoped to selected MCP servers no longer fails with a "length of body.tools must be greater or equal than 1" error when a server follows the policy tool rule. (Author: @vishalg0wda)
- Hook sessions stay with the project that opened the chat #5239 - Hook ingest pins a session to the project that first created its chat, so a later request carrying a different project header cannot stamp messages onto that chat. Chat list counts and last-message times ignore those sibling-project rows. (Author: @speakeasyforgebot)
