> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get agent policy

> **Token scope:** `account` · `org` · `project` — read-only tokens allowed.



## OpenAPI

````yaml /openapi/project.json get /projects/{projectId}/agent-policy
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/agent-policy:
    get:
      tags:
        - Governance
      summary: Get agent policy
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        allowed.
      operationId: getAgentPolicy
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  policy:
                    type: object
                    properties:
                      mode:
                        anyOf:
                          - type: string
                            enum:
                              - full_access
                          - type: string
                            enum:
                              - read_only
                          - type: string
                            enum:
                              - branch_specific
                          - type: string
                            enum:
                              - customize
                      protectedBranchIds:
                        type: array
                        items:
                          format: uuid
                          type: string
                      rules:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      branchDeveloperRules:
                        deprecated: true
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      updatedBy:
                        type: string
                      updatedAt:
                        type: string
                    required:
                      - mode
                      - protectedBranchIds
                      - rules
                      - branchDeveloperRules
                  agentSessionEpoch:
                    type: integer
                  actions:
                    type: array
                    items:
                      type: string
                  actionCatalog:
                    type: array
                    items:
                      type: object
                      properties:
                        action:
                          type: string
                        group:
                          type: string
                        groupLabel:
                          type: string
                        label:
                          type: string
                        hint:
                          type: string
                        editable:
                          description: >-
                            false when a rule naming this action is refused as a
                            fixed invariant
                          type: boolean
                        fixedDecision:
                          description: >-
                            what a non-editable action resolves to under the
                            restricted modes; null when editable. full_access
                            allows even the denied ones, so this and the current
                            decision disagree for exactly what stops being
                            allowed when full access is left
                          anyOf:
                            - anyOf:
                                - type: string
                                  enum:
                                    - allow
                                - type: string
                                  enum:
                                    - deny
                                - type: string
                                  enum:
                                    - approve
                            - type: 'null'
                      required:
                        - action
                        - group
                        - groupLabel
                        - label
                        - hint
                        - editable
                        - fixedDecision
                  defaultRules:
                    type: object
                    properties:
                      project:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      unprotectedBranch:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      protectedBranch:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                    required:
                      - project
                      - unprotectedBranch
                      - protectedBranch
                  effectiveRules:
                    type: object
                    properties:
                      project:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      unprotectedBranch:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      protectedBranch:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                    required:
                      - project
                      - unprotectedBranch
                      - protectedBranch
                  bootstrapRules:
                    type: object
                    properties:
                      project.create:
                        type: string
                        enum:
                          - allow
                    required:
                      - project.create
                  ruleNotes:
                    type: array
                    items:
                      type: string
                required:
                  - policy
                  - agentSessionEpoch
                  - actions
                  - actionCatalog
                  - defaultRules
                  - effectiveRules
                  - bootstrapRules
                  - ruleNotes
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````