Skip to content

Commit aa24bbf

Browse files
agent feedback
Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
1 parent adabf69 commit aa24bbf

1 file changed

Lines changed: 3 additions & 4 deletions

File tree

  • content/manuals/ai/sandboxes/governance

content/manuals/ai/sandboxes/governance/org.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -197,10 +197,9 @@ Only organization rules determine what access is permitted, and local allow
197197
rules can't loosen those restrictions. The same applies to filesystem policies:
198198
local filesystem allow rules are replaced by organization rules entirely.
199199

200-
Local deny rules are still evaluated for network access and layer on top of
201-
the organization policy. Developers can use `sbx policy deny` to further
202-
restrict network access beyond what the org policy allows, even when governance
203-
is active.
200+
Local deny rules are still evaluated and layer on top of the organization
201+
policy. Developers can use `sbx policy deny` to further restrict access beyond
202+
what the org policy allows, even when governance is active.
204203

205204
For how a user's organization policies are evaluated together, see
206205
[Policy concepts](concepts.md#rule-evaluation).

0 commit comments

Comments
 (0)