Group Policy for AI - Every Repo, Every Machine, One Source of Truth
Define CLAUDE.md, .cursorrules, Copilot instructions, MCP allowlists, and memory packs centrally, then push them fleet-wide with drift detection behind them.
AI Standards Documented Are AI Standards Ignored
Engineering organizations write down how AI tools should be configured - which MCP servers are allowed, what the agent should never touch, which conventions to follow - and then rely on every developer to copy that configuration into every repository by hand.
In practice the payments repo and the marketing site end up with the same guardrails, new hires start from whatever config they inherited, and nobody knows which machines are running a modified version.
Templates, Assignment, Merge, Reconciliation
Profiles are authored once and assigned to teams, repositories, or devices. The agent applies them where the code actually lives.
- Managed file types - CLAUDE.md and memory packs, .cursorrules, Copilot instructions, MCP server allowlists, tool-specific settings
- Template library - build once, assign to teams, repos, or devices
- Discover and assign - find configs already sitting on endpoints and bring them under management
- Fleet-wide deployment - push a config change to every managed repo in one click
- Drift detection - alert when a developer modifies a managed config, with auto-reconciliation
- Promotion workflow - promote a good local config into a managed template
- Redaction - sensitive values are stripped from profiles before distribution
Hierarchical merge strategies
When several assignments apply to the same repo, the merge is deterministic per field.
| Strategy | Behavior |
|---|---|
| concat_dedup | Lists merge; later wins on name conflict |
| most_specific | Highest-priority assignment wins outright |
| min_wins | Safer-floor semantics for ceilings |
| max_wins | Safer-floor semantics for floors |
| merge_dict | Shallow merge, most-specific value per key |
Template Library and Drift View
Controls This Evidences
- ISO A.8.28
- Secure coding - per-repo AI config enforcement via managed CLAUDE.md and .cursorrules
- NIST SA-11
- Developer testing and evaluation - standardized AI guardrails in the development pipeline
- NIST CM-5
- Access restrictions for change - managed configuration with drift reconciliation
See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io