# What enforces each policy field

`application-policy.yaml` is a custom application policy. It is not applied by `CreateHarness`, `create_harness()`, or the Strands CLI.

| Field | What actually stops the action |
| --- | --- |
| `scope.allowed_paths` | Application diff check in `harness_policy.py`, or a sandbox that cannot see other paths |
| `scope.allowed_commands` | A command allowlist in the tool runner. A prompt line does not do this |
| `iterations.max_iterations` | Your loop counter, or AgentCore `maxIterations` on `InvokeHarness` (service default 75 as of 11 Oct 2026) |
| `iterations.deadline_seconds` | Your deadline, or AgentCore `timeoutSeconds` (service default 3600) |
| `cost.stop_after_model_calls` | Application code that refuses another model call. Not AWS Budgets |
| `retries.require_reconcile_when_outcome_unknown` | `retry_decision()` in `harness_policy.py` |
| `data.redact_secrets_in_traces` | The logger you ship. The policy file does not redact |
| `data.persist_raw_prompts: false` | The trace sink omitting prompt bodies |
| `approvals.required_operations` | `require_approval()` plus, on AWS, IAM and Gateway Cedar for the tools you expose |
| `verification.required_checks` | `verify_coding_task()` running the commands outside the model |
| `verification.agent_self_approval_counts: false` | Do not add a tool the model can call to mark the task done |

AgentCore fields you set on the service, separately from this file:

- `maxIterations`, `timeoutSeconds`, `maxTokens` on invoke
- `idleRuntimeSessionTimeout` (default 900 seconds) and `maxLifetime` (default 28800 seconds)
- Truncation: `sliding_window` or `summarization`

Those defaults are from the [harness operations page](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/harness-operations.html) checked 11 October 2026. Re-read them before you copy a number into a runbook.
