| Git | dont_push_to_main, require_branch_prefix, max_files_per_commit, dont_delete_branch, dont_merge_to_main | Direct pushes to main, wrong branch names, blast radius |
| Database | dont_delete_row, dont_delete_without_where, dont_update_without_where, protect_tables, block_ddl | Dangerous deletes, unscoped updates, DDL like DROP TABLE |
| Filesystem | dont_delete_file, restrict_paths, block_extensions | File deletions, path traversal, sensitive files (.env, .key) |
| Access | contractor_cannot_write_pii, require_actor_role, require_user_role, dont_read_sensitive_tables, dont_read_sensitive_paths, require_clearance_for_path | Unauthorized access, PII exposure |
| CRM | dont_duplicate_contacts, limit_tasks_per_contact | Duplicate records, rate limiting |
| Time | within_maintenance_window, code_freeze_active | Actions outside allowed hours, during code freezes |
| Slack | require_channel_allowlist, block_dms | Off-list channel posts, direct messages to users |
| Email | no_mass_emails, no_repeat_emails | Mass email blasts, spamming the same recipient |
| Cloud Storage | dont_delete_without_human_ok | S3/GDrive deletions without cryptographic HITL approval |