JetBrains Central Console eap Help

AI policies

An AI policy is a set of access settings that controls which AI tools, agents, MCP servers, and BYOK providers are available to users, groups, and service accounts in your organization.

On the AI policies page in JetBrains Central Console, you can create, configure, assign, duplicate, and delete policies.

Default policy

Every organization has a default policy that applies to all users, groups, and service accounts with AI access. The default policy provides the base settings for all principals and lets you control the availability of AI-powered features at the organization level. Changing one of its settings also changes it for every custom policy that uses that default value. If a custom policy has set its own value for that setting instead, changing the default policy has no effect on it.

The default policy is automatically created for every organization, and all users and service accounts with AI access are automatically assigned to it. You can edit all of its settings, but you cannot delete or duplicate it, or change its principals.

Custom policies

To apply different settings to specific principals, you need to create custom policies. A custom policy inherits all its settings from the default policy. You customize only the settings you need. For most settings, you override the inherited value with your own. For list settings such as agents, you can also add your own items or disable the ones inherited from the default policy. Your changes apply only to the principals assigned to that custom policy, while the settings you don't change keep following the default policy when it changes. For more details, see Inherited, overridden and changed settings.

Inherited, overridden and changed settings

A custom policy inherits its settings from the default policy, so any changes to the default policy affect the inherited settings in the custom policy. When you set your own value for a setting, it becomes overridden, even if that value matches the current default policy value. An overridden setting no longer follows the default policy: its value doesn't change even if the default policy changes later.

A setting can have unsaved changes. If the current value of the setting differs from the last saved value, it is shown as changed until you save the policy. For details on how these states are shown while you edit a policy, see Setting state indicators.

Multiple policies assigned to a principal

Users, groups, and service accounts can be assigned to multiple policies: the default policy and one or multiple custom policies. In this case, the effective settings for the principal are calculated by merging the settings from all assigned policies according to the following rules:

  • A setting that a custom policy doesn't define is inherited from the default policy.

  • When a custom policy defines a setting differently from the default policy, and they contradict, the custom policy's value takes precedence. It overrides the default policy value for principals assigned to that custom policy.

  • When multiple custom policies define conflicting values for the same setting, the restrictive value applies. A disabled item or toggle stays unavailable even if another assigned policy enables it.

  • When the settings from multiple policies don't conflict, the settings are combined into the union of all values.

For agents, the All available agents toggle is resolved first, and the restrictive state wins: if at least one of the principal's assigned policies has All available agents turned off, the effective state is off. The effective set of agents is then merged only from the agents explicitly listed in the policies where All available agents is off, according to the rules above.

The following examples show how effective settings are calculated for a principal assigned to the default policy and one custom policy:

Use case

Default policy

Custom policy

Effective settings

Grant access to specific users

Third-party AI providers are disabled.

Third-party AI providers are enabled.

Third-party AI providers are enabled. The custom policy overrides the default policy.

Extend the default set

The Claude agent is allowed.

The Junie agent is added.

Both the Claude and Junie agents are available. The two policies are combined.

Reduce the default set

The Claude agent is allowed.

The Claude agent is explicitly disabled.

The Claude agent is unavailable. The custom policy overrides the default policy.

The following examples show how effective settings are calculated for a principal assigned to the default policy and two custom policies:

Use case

Default policy

Custom policy A

Custom policy B

Effective settings

Resolve a conflict between custom policies

The Claude agent is allowed.

The Claude agent is allowed (the inherited state is kept).

The Claude agent is explicitly disabled.

The Claude agent is unavailable for a principal assigned to both A and B. The restrictive setting wins.

Combine settings from custom policies

The Claude agent is allowed.

The Junie agent is added.

The Codex agent is added.

The Claude, Junie, and Codex agents are all available. Non-conflicting settings from all assigned policies are combined.

Resolve different All available agents states

All available agents is on.

All available agents is on (the inherited state is kept).

All available agents is off, and the agent list is reduced to the Claude agent only.

Only the Claude agent is available for a principal assigned to both A and B. The toggle resolves to off because policy B turns it off, so only the agents explicitly listed in the policies where the toggle is off are merged.

Managing policies

Create a new policy

  1. In the sidebar, under AI governance, select Policies.

    If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.

  2. In the upper right corner, click Add policy.

  3. In the New policy dialog, specify a policy name and, optionally, a description.

  4. Click Add.

  5. On the policy page, configure the policy settings and assign users, groups, and service accounts to the policy.

  6. In the upper right corner, click Save.

The policy is created and listed in the AI policies table.

Duplicate a policy

Duplicating a policy creates a separate copy of the source policy's settings. Like any custom policy, the duplicate policy inherits the settings it doesn't define from the default policy.

  1. In the sidebar, under AI governance, select Policies.

    If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.

  2. In the table, click Ellipsis icon next to the target policy, and select Duplicate policy.

    If you are on the policy page, click Ellipsis icon in the upper right corner and select Duplicate policy.

  3. In the dialog, specify a new policy name and, optionally, a description.

  4. Click Duplicate.

  5. On the policy page, configure the policy settings and assign users, groups, and service accounts to it, since the principal assignments from the source policy are not copied.

  6. In the upper right corner, click Save.

The policy is created and listed in the AI policies table.

Delete a policy

  1. In the sidebar, under AI governance, select Policies.

    If you don't see this page, or the controls on this page are inactive, your role doesn't have the necessary permissions.

  2. In the table, click Ellipsis icon next to the target policy, and select Delete policy.

    If you are on the policy page, click Ellipsis icon in the upper right corner and select Delete policy.

  3. In the dialog, specify the policy name to confirm the deletion and click Delete.

A success message appears in the lower right corner once the policy is deleted.

14 August 2026