Policies
A Policy in Helio Audit represents standards that shape how Reviews and findings are applied across Repositories. Policies help Organizations keep AI code review and security expectations consistent as teams and projects scale.
Why Policies matter
Without shared standards, Review quality varies by team and scanner configuration drifts over time. Policies support:
- Consistent Reviews across engineering teams
- Clear, actionable security findings on Pull Requests
- Reusable Organization guidance so standards apply across projects (skills and related developer-experience workflows)
What Policies influence
Policies can guide expectations such as:
- Which Review behaviors matter for a Repository or Workspace
- How security Issues (including secrets and dependency findings) should be treated relative to quality Suggestions
- Which Organization standards or reusable skills apply during analysis and remediation
Create and assign Policies using the configuration and controls provided with your Helio Audit installation.
Relationship to other concepts
| Concept | Relationship to Policy |
|---|---|
| Review | Policies shape what a Review emphasizes and how results are interpreted |
| Issue / Suggestion | Policies help prioritize or classify outcomes |
| Workspace / Organization | Policies are typically scoped to Organizational boundaries |
| Skills | Reusable guidance that encodes standards developers and agents can apply |
Typical workflow
When to define Policies
- Consistent AI Reviews across many Repositories
- Clearer security gates on Pull Requests
- Shared remediation expectations for common Issue classes