# rpk ai policy create

> For the complete documentation index, see [llms.txt](https://docs.redpanda.com/llms.txt). Component-specific: [agentic-data-plane-full.txt](https://docs.redpanda.com/agentic-data-plane-full.txt)

---
title: rpk ai policy create
latest-operator-version: v26.2.1
latest-console-tag: v3.10.0
latest-connect-version: 4.105.0
latest-redpanda-tag: v26.2.1
docname: rpk/rpk-ai/rpk-ai-policy-create
page-component-name: agentic-data-plane
page-version: master
page-component-version: master
page-component-title: Agentic Data Plane
page-relative-src-path: rpk/rpk-ai/rpk-ai-policy-create.adoc
page-edit-url: https://github.com/redpanda-data/adp-docs/edit/main/modules/reference/pages/rpk/rpk-ai/rpk-ai-policy-create.adoc
description: "Create a Cedar authorization policy: the allow/deny gate that decides WHETHER a principal may call a tool."
page-git-created-date: "2026-07-28"
page-git-modified-date: "2026-08-06"
---

<!-- Source: https://docs.redpanda.com/agentic-data-plane/reference/rpk/rpk-ai/rpk-ai-policy-create.md -->

Create a Cedar authorization policy: the allow/deny gate that decides WHETHER a principal may call a tool.

The Cedar body must contain exactly one statement; scope the resource to your MCP server, for example:

```text
permit(principal, action == Action::"dataplane_adp_mcpserver_tools_call",
       resource == McpServer::"servicenow");
```

Data shaping (`masking`, dropping, row filtering) is NOT configured here. It lives on the MCP server’s data policies (`rpk` ai mcp …​), not in Cedar text; the @redact\_mask / @redact\_drop annotations are gone.

> 📝 **NOTE**
>
> This command was introduced in ai version 0.2.26.

## [](#usage)Usage

```bash
rpk ai policy create [flags]
```

## [](#flags)Flags

| Value | Type | Description |
| --- | --- | --- |
| --cedar | string | inline Cedar policy text. Mutually exclusive with --cedar-file. |
| --cedar-file | string | path to a file containing the Cedar policy text (.cedar). Mutually exclusive with --cedar. |
| --description | string | human-readable description. |
| --display-name | string | human-readable display name. |
| --name | string | policy id (required; lowercase letters, numbers, hyphens). |

## [](#global-flags)Global flags

| Value | Type | Description |
| --- | --- | --- |
| --config | string | Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml. |
| -X, --config-opt | stringArray | Override rpk configuration settings; -X help for detail or -X list for terser detail. |
| --ignore-profile | bool | Ignore rpk.yaml and redpanda.yaml; use default settings. |
| --profile | string | rpk profile to use. |
| -v, --verbose | bool | Enable verbose logging. |