Configuring policies
Policy settings control which AI tools, agents, MCP servers, and BYOK providers are available to users, groups, and service accounts under the policy. You can configure the policy settings in the corresponding tabs on the policy page.
A custom policy inherits each setting from the default policy until you override or extend it. For details on these states, see Inherited, overridden and changed settings. To learn how they appear on this page, see Setting state indicators.
Edit a policy
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the tab you want to edit: General,
Agents, or Tools.
Make the necessary changes on the selected tab. For all available settings, refer to Policy settings.
In the upper right corner, click Save.
In the dialog, review the summary of changes and click Save to apply them.
A success message appears in the lower right corner once changes are saved. It may take a few minutes for the changes to take effect. The duration depends on the number of users, groups, and service accounts assigned to the policy.
Setting state indicators
Changes to policy settings are not saved automatically. You need to apply your changes by clicking Save. Until you save, each changed setting is marked with a yellow bar, and the tab shows a yellow dot. If you try to leave the policy page while there are unsaved changes, you are prompted to either Save or Discard changes.
While you edit a custom policy, a colored bar to the left of a setting shows its state:
No bar: the setting is inherited and saved. The custom policy doesn't define its own value for it, so the setting uses the default policy value and changes automatically when the default policy changes.
Yellow bar: the setting has an unsaved change. Its current value differs from the last saved value because you either overrode an inherited setting or reverted a saved override. Saving resolves the yellow bar.
Blue bar: the setting is a saved override. The custom policy defines its own value for it and no longer follows the default policy. So later changes to the default policy don't affect this setting.
A colored dot to the left of a tab name indicates that the tab contains such settings: a yellow dot indicates unsaved changes, a blue dot indicates saved overrides.
To revert a setting to the value inherited from the default policy, hover over the setting and click to the left. The hover revert icon applies to toggles and selectors. For agents and MCP servers, you revert an item from its context menu: click
in the corresponding row and select Reset.
The icon is shown only if the setting is overridden. The result depends on whether the override was already saved:
If the override has not yet been saved (the yellow bar is shown), the setting returns to the inherited state immediately (no bar).
If the override was already saved (the blue bar is shown), reverting sets the value back to the inherited one but counts as a new unsaved change, so the blue bar turns yellow. You must click Save for the setting to become inherited again.
For example, the Cloud tasks setting can go through these states:
In a new custom policy, it is inherited from the default policy. No bar is shown.
You disable it. The setting now has an unsaved change, and the yellow bar is shown.
You click Save. The override is saved, and the blue bar is shown.
Later, you click
. The value returns to its inherited enabled state, but the revert has not been saved yet, so the yellow bar is shown.
You click Save again. The setting is inherited again, and no bar is shown.
Policy settings
General settings
On the General tab, the following settings are available:
Setting | Description |
|---|---|
Name | Policy name. |
Description | Optional description that explains the purpose of the policy. |
Cloud tasks | Determines whether users and service accounts under the policy can use remote environments managed by JetBrains to run AI agent sessions. When enabled, users and service accounts are allowed to use cloud-based AI agents. Default value: enabled. |
AI provider | Specifies the AI provider used for all AI-powered features. The features that don't support the selected provider's models are not available, and agents appear greyed out in the AI tools (AI Assistant and JetBrains Air). Default value: JetBrains AI. |
MCP servers
On the MCP tab, you can control which Model Context Protocol (MCP) servers are available to users, groups, and service accounts under the policy. MCP servers are not available to principals until you add them to the policy.
In the default policy, only the MCP servers you've added are listed. Every server you add to the default policy becomes available to all principals with AI access in your organization, and every custom policy receives it automatically.
A custom policy starts with all the MCP servers inherited from the default policy. In a custom policy, you can extend this set by adding MCP servers that are not in the default policy, or restrict it by disabling servers inherited from the default policy.
The Other MCP servers setting determines whether users, groups, and service accounts can use MCP servers added locally beyond those listed in the policy. By default, the option is disabled. In a custom policy, this setting is inherited from the default policy and follows the same inherited, overridden, and changed states as the settings on the General tab.
The MCP servers table shows the following for each server:
Whether the server is enabled or disabled. A disabled server stays in the table, marked with the Disabled label, but it is not available to the principals under the policy.
Whether the server is inherited from the default policy or added directly to this policy. An inherited server is marked with the Inherited label.
Whether the server is Command or Remote. For details, see MCP servers.
When a principal is assigned to multiple policies, it gets access to the combined list of MCP servers allowed across its policies.
Add an MCP server
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the MCP tab.
Click Add MCP server and select a server from the dropdown, which lists the organization's MCP servers that are not yet in the policy.
The MCP server appears in the table and is enabled for the policy.
Disable an MCP server
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the MCP tab.
In the MCP servers table, find the server you want to disable.
In the corresponding row, click
and select Disable MCP server.
The MCP server is marked with the Disabled label and is no longer available to the principals under the policy. Disabling an inherited server overrides the default policy and takes precedence when the effective settings are calculated. For more details, see Multiple policies assigned to a principal.
To enable the MCP server, click in the corresponding row and select Enable MCP server. To discard the override on an inherited server and return to the state defined in the default policy, select Reset instead. Reverting follows the same rules as other settings.
Remove an MCP server
You can remove only an MCP server added directly to a policy. In the default policy, every server is added directly, so you can remove any of them. In a custom policy, this works only for servers added directly to that policy; to make a server inherited from the default policy unavailable, disable it instead.
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the MCP tab.
In the MCP servers table, find the MCP server you want to remove.
In the corresponding row, click
and select Remove MCP server.
In the dialog, click Remove to confirm.
The MCP server is removed from the table and is no longer available to the principals under the policy.
Agents
On the Agents tab, you can control which AI agents are available to users, groups, and service accounts under the policy.
The All available agents toggle determines how the set of available agents is managed:
When All available agents is on, all agents available in your organization at that time are available to principals under the policy. The Agents table shows the full list, and you can't add, disable, or remove individual agents.
When All available agents is off, only the agents listed in the Agents table are available. You can add, disable, and remove agents. Turning All available agents back on discards the manually managed list and restores the full list of agents.
In the default policy, All available agents is on initially, so every principal with AI access in your organization can use all available agents. To limit the default policy to a specific set of agents, turn off All available agents.
A custom policy inherits both the All available agents toggle state and the agent list from the default policy. The toggle behaves the same way as in the default policy: to customize the set of agents for its principals, turn off All available agents, and the inherited list becomes editable. The agents inherited from the default policy are marked with the Inherited label.
When All available agents is off, the Agents table shows the following for each agent:
Whether the agent is enabled or disabled. A disabled agent stays in the table, marked with the Disabled label, but it is not available to the principals under the policy.
Whether the agent is inherited from the default policy or added directly to this policy. An inherited agent is marked with the Inherited label.
Whether the agent is sourced from the global agent registry or added manually at the organization level as a custom agent. A tag in the row shows the source.
When a principal is assigned to multiple policies, it gets access to the combined list of agents allowed across its policies. If the assigned policies have different All available agents states, the toggle is resolved to the restrictive state first: it is off if at least one of the policies has it turned off.
Add an agent
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the Agents tab.
Click Add Agents and, in the dialog, select one or multiple agents from the dropdown, then click Add.
Only organization's agents that are not yet in the policy can be added. To add all available agents at once, click Add all N agents.
The agents appear in the table and are enabled for the policy.
Disable an agent
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the Agents tab.
In the Agents table, find the agent you want to disable.
In the corresponding row, click
and select Disable agent.
The agent is marked with the Disabled label and is no longer available to the principals under the policy. Disabling an inherited agent overrides the default policy and takes precedence when the effective settings are calculated. For more details, see Multiple policies assigned to a principal.
To enable the agent, click in the corresponding row and select Enable agent. To discard the override on an inherited agent and return to the state defined in the default policy, select Reset instead. Reverting follows the same rules as other settings.
Remove an agent
You can remove only an agent added directly to a policy. In the default policy, every agent is added directly, so you can remove any of them. In a custom policy, this works only for agents added directly to that policy; to make an agent inherited from the default policy unavailable, disable it instead. If inherited agents are included in a bulk removal, they are disabled instead.
In the sidebar, under AI governance, select Policies.
If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.
In the table, click the policy name to open its page. If you are already on the policy page, proceed with the next step.
On the policy page, select the Agents tab.
In the Agents table, find the agent you want to remove.
In the corresponding row, click
and select Remove agent.
To remove multiple agents, select them using the checkboxes in the first column and click Remove Agents.
In the dialog, click Proceed to confirm.
The agents are removed from the table and are no longer available to the principals under the policy.
To control whether users and service accounts can use local agents via the Agent Client Protocol (ACP), see the Tools settings.
Tools
On the Tools tab, you can configure AI tools available to users, groups, and service accounts under the policy.
AI Assistant
AI Assistant is an integrated tool in JetBrains IDEs that enhances software development with AI-powered features.
In the AI Assistant card, you can configure the following settings:
Setting | Description |
|---|---|
Third-party AI providers | Determines whether users and service accounts can use a personal API key to connect to locally installed LLMs, bypassing the organization-level AI provider configuration. This enables local Bring Your Own Key (BYOK) connections. To learn more, refer to the AI Assistant documentation. Default value: enabled. |
Custom ACP agents | Determines whether users and service accounts can use their own local agents via the Agent Client Protocol (ACP), beyond those configured at the organization level. This is separate from agents configured for the policy on the Agents tab. Default value: enabled. |