Skip to content

All posts tagged “infrastructure-as-code”

Tag: infrastructure-as-code

Governed Growth, Part 3: Default-Deny for Model Capabilities

Parts 1 and 2 argued that a capability's trust boundary is a separate decision from the model's. Part 3 is the runbook that makes the decision stick: the org-policy constraints that gate partner web search and structured outputs, set once at the organization tier by gcloud and Terraform, plus the seams org-policy doesn't reach—VPC Service Controls, request-response logging, the grounding-provider choice. Which toggle, at which scope, with deny-wins precedence, so a good-faith developer can't trip a data path nobody chose.