Policy files are not runtime interception
Repository policy can declare protected files, command restrictions, workflow review, redaction, and approval paths. It should not be called enforced unless actual operations are intercepted.
It must fit developer workflow
Controls that slow every edit will be bypassed. CapitalGuard generates focused guardrail starters that developers can install around high-impact paths first.
Detection comes before prevention
The right policy depends on the exposure report. CapitalGuard scans first, then turns the findings into practical controls for the customer's current scope.
