---
title: "Implicit deny"
description: "The authorisation rule that a request no policy explicitly permits is refused."
canonical: https://aigovernanceengineer.com/glossary/implicit-deny
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Implicit deny

The authorisation rule that a request no policy explicitly permits is refused. Cedar denies by default and lets any matching forbid override every permit [1]; an agent's tool allow-list works the same way, so an unlisted tool is blocked without a rule of its own.

- Developed in: [ch. 23, The tool allow-list](https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list); [Toolkit: Policy Card builder](https://aigovernanceengineer.com/toolkit/policy-card#pc-engines)
- Chapters: [ch. 08, Regulatory Map](https://aigovernanceengineer.com/bok/regulatory-map) · [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-implicit-deny

## Sources

[1] Authorization (Cedar Policy Language Reference Guide) (no request is allowed unless a permit policy grants it, so the default decision is Deny; any satisfied forbid overrides every permit). Cedar. n.d. (accessed 2026-09-25). https://docs.cedarpolicy.com/auth/authorization.html (verified: primary)
