Skip to main content
A policy is a governance rule attached to a perimeter that controls what the workloads in it can access. Policies are how your organization sets guardrails on packages, models, compute, and container images, so that secure, approved access is the default rather than something each user configures.

Why policies matter

Governance only works if it’s enforced consistently. Instead of relying on every data scientist to configure things correctly, an administrator defines policies once, at the perimeter level, and the platform applies them to every workload that runs in that perimeter. This gives your organization central control while keeping the experience simple for users, who work within the guardrails without having to manage them. Policies are enforced by the platform when a workload is admitted to run. A user cannot bypass a policy from their own code or environment.

Kinds of policy

Different policies govern different resources:

How policies are applied

Because policies live on the perimeter, they apply automatically to everything that runs there. When the platform resolves packages for a workload, channel policies determine which packages it can draw on. When a user browses the model catalog, model access policies determine which models they see. When a run starts, task resource limits and the image allowlist determine what its tasks can request and run. Administrators can adjust a perimeter’s policies at any time, and the changes apply to subsequent work in that perimeter.

Managing policies

Policies are configured per perimeter. For configuration details, see Channel governance and Model governance.