Skip to main content
Most policies require an Enterprise plan. Environment timeout is available on Core and Enterprise.
Go to Settings → Organization → Policies to configure. Only administrators can access policies. Organization Policies Key behavior:
  • Changes take effect immediately for new actions
  • Existing environments are not affected

Available policies

PolicyPurpose
Editor restrictionsStandardize which editors and versions your team can use
Environment timeoutLimit auto-stop timeout options
Environment limitsCap total and concurrent environments per user
Maximum environment lifetimeSet a maximum age for environments and optionally block restarting expired ones
Environment and project creationRestrict project creation to admins; members must use existing projects
Port sharingControl user-initiated port exposure from environments
Default imageSet default devcontainer image
Auto-deleteSet retention period for archived environments
Security agentsDeploy CrowdStrike Falcon to all environments
Executable deny listBlock specific executables from running in environments
Command deny listBlock specific commands from Ona Agent execution
SCM toolsControl Ona Agent’s GitHub/GitLab access
Looking for default environment image settings? See Default image policy.

Tracking changes

All policy changes are recorded in audit logs, including who changed what and when.

Best practices

  • Start gradually: Begin with moderate limits and adjust based on usage patterns
  • Review regularly: Check usage patterns quarterly or after team changes
  • Avoid over-restricting: Use project-based creation for control without blocking productivity