Choosing your first policy

The defaults are chosen so that switching Sentilai on changes nothing about how your developers work. That is deliberate. The mistake to avoid is turning everything to block on day one: the tools break in ways your team cannot diagnose, and they learn that the way to get work done is to stop using the governed path.

Here is a sequence that works.

Week 1 — see everything, block almost nothing

At the end of the week, MCP Inventory shows you what your team is really connected to. Most organizations find at least one thing they did not know about.

Week 2 — decide about MCP

Go through the inventory and set an explicit rule per server: allow the ones you recognize, block the ones you do not. Then turn on Require approval for new MCP servers with a pending action of Report or Warn, so anything new shows up before it becomes normal.

Week 3 — start enforcing

What to tell your team

Tell them before you start, not after the first block. Two facts do most of the work: their subscription still pays for their usage in subscription mode, and nobody is reading their prompts unless prompt capture is on — in which case say so explicitly.


Revision #6
Created 2026-08-02 10:19:50 UTC by Sentilai Docs
Updated 2026-08-04 08:39:35 UTC by Sentilai Docs