Open this worksheet in a web browser
This page is showing in a file preview, which cannot run the worksheet, so its buttons do nothing here. On a phone, the Files app, a message attachment, or an AirDrop preview all open files this way.
Use the online worksheet instead: 3fold-labs.github.io/ai-agent-rules. On a computer, open this file with Chrome, Safari, Edge, or Firefox.
Set the rules once.
Share them with every AI agent.
100 questions decide what your AI agents can do, what needs your approval, and what is off limits. Pick the track that fits you, answer in any order, and download a policy to give any assistant or agent, for personal work or a team.
Every question shows a suggested answer you can accept or change. Your answers save in this browser only. Save them to a file to keep them.
Who are these rules for?
Pick one. Each track has its own 100 questions and keeps its own answers. You can do both.
Some saved answers could not be read
Some saved answers in this browser could not be read. They are kept aside, and you can download them.
Builder track · 100 questions
Which parts apply to you?
Uncheck any part that does not fit your life or work. It turns off: its questions read as Doesn’t apply in your policy, and any answers in it stay saved for when you turn it back on.
Suggestions fill only the questions you have not answered. Each one shows as suggested until you choose an answer or edit its notes.
A suggested DENY stays a firm no until you change it.
Make it yours
These details go at the top of your policy. Nothing on this page is sent anywhere. Anyone who uses this browser can see saved answers, so keep passwords and other secrets out of them.
ALLOW means act within the scope you write. ASK means get your yes first. DENY means don’t. Doesn’t apply marks a question outside your setup. Unanswered questions grant no permission.
Additional boundaries (optional)
Name folders, spend caps, recipients, and other boundaries. If a rule conflicts with another rule or a boundary, the agent must stop and ask. These notes do not silently override a DENY.
Coding tool settings cannot store limits, so any text here turns every allow in them into ask. Your policy keeps your ALLOW answers and these limits.
Download your policy
Before you download
Check what your agents will read. Each item opens its question.
What you allowed (0)
These run without asking, within the notes you wrote.
Your additional boundaries (0)
Unanswered (0)
Your policy tells agents to ask you first about each of these.
Suggested or needing review (0)
Choose an answer or edit its notes to mark it reviewed.
Give the policy file to each AI agent you use and say: “Follow this policy.” Unanswered questions stay unresolved, never a silent yes.
0 characters in your policy.
Coding tool settings
Coding tools can apply part of your policy themselves. Rules in a tool’s settings are not part of your agent’s instructions, and every answer also stays in your policy.
Tool settings are a strong guardrail, not a lock. A tool can miss a command written another way, for example with its options in a different order or wrapped in sh -c, so your policy still applies.
Which coding tool do you use?
Choose your tool to see its files, where to save them, and the rules to add.
Claude Code
Save it as.claude/settings.json in your project folder.
Already have that file?Add these three permission lists to its permissions instead of replacing the file, so your other settings stay.
Remove these rules
Add these rules
These are the rules you last said are in your file.
Check it loadedRun /permissions in Claude Code. Your allow, ask, and deny rules are listed there.
Codex
Save them as.codex/rules/ai-agent-rules.rules and .codex/config.toml in your project folder. Codex loads them when you trust the project. The rules file also works in ~/.codex/rules/.
Updating your rules file?The rules file holds only these rules. Replace the whole file with the new download or with these rules. Never add them to the end of the file: when two rules match a command, the stricter one applies.
Already have a config.toml?Set these two lines in it.
Check it loadedRun codex execpolicy check --pretty --rules .codex/rules/ai-agent-rules.rules -- git push --force and read the decision it prints.
Gemini CLI
Save it as~/.gemini/policies/ai-agent-rules.toml in your home folder.
Updating that file?It holds only these rules. Replace the whole file with the new download or with these rules. Never add them to the end of the file: when two rules match a command, the stricter one applies.
Check it loadedGemini CLI reads every .toml file in ~/.gemini/policies/ when it starts.
Cursor
Guidance only. Cursor applies these instructions only in Auto-review mode and does not treat them as security.
Save it as.cursor/permissions.json in your project folder. This file applies to the Cursor editor. The Cursor CLI has its own permissions.
Already have that file?Add this allowlist and these instructions to it instead of replacing it.
Remove these rules
Add these rules
These are the rules you last said are in your file.
Check it loadedIn Cursor Settings, choose Auto-review as the Run Mode. The terminal allowlist there shows the file’s commands.
Cursor reads these rules as guidance, so they do not count as backing any answer.
Your policy works on its own. Every answer is in it as instructions for your agent.
Give your agent this compact policy together with the tool file.
Try it
Ask your agent to run . The tool should block it. The command is harmless if it runs.
Backed by tool rules
Each of these has a rule in Claude Code, Codex, and Gemini CLI, and no notes. It also stays in your policy.
Instructions only
These rely on your policy. Some also get a rule that covers only some forms of the action (partial) or cannot hold your notes.
Your Personal rules stay as instructions in your policy, because everyday assistants do not accept permission files.
Check how your agent reads your rules
After your agent reads your policy, ask it these questions. Its answers show how it understands your rules, not a guarantee of how it will act. Each question comes from your own answers, with your notes when you wrote any, and shows what your policy expects.
Finished both tracks?
Give each agent the policy for the work it does. An agent that does both gets both files. When two answers differ, the stricter one applies.
Clear this track
Removes every Builder track answer, note, section choice, profile field, and exception saved in this browser. Your other track and your downloaded files stay as they are.