Implicit deny

The authorisation rule that a request no policy explicitly permits is refused. Cedar denies by default and lets any matching forbid override every permit 1; an agent's tool allow-list works the same way, so an unlisted tool is blocked without a rule of its own.

Developed in
ch. 23, The tool allow-list
Toolkit: Policy Card builder
Chapters
ch. 08, Regulatory Map · ch. 23, AI Agents
Source
1 numbered reference, listed below

Where it is used

The term is not used under this name in running prose; the sections listed under "Developed in" treat it.

Sources

  1. [1] Authorization (Cedar Policy Language Reference Guide) (no request is allowed unless a permit policy grants it, so the default decision is Deny; any satisfied forbid overrides every permit). Cedar. n.d. (accessed 2026-09-25). https://docs.cedarpolicy.com/auth/authorization.html (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Implicit deny. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/implicit-deny. CC BY 4.0

BibTeX

@misc{aige2026implicitdeny,
  author  = {Jorge García Aibar},
  title   = {{Implicit deny}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/implicit-deny}
}