> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Up Formal with Recipes

> Answer a few questions and let a recipe create the policies, rules, and workflows for a common outcome

## Overview

[Recipes](https://app.formal.ai/recipes) are guided setups for common outcomes, such as blocking agent Git pushes or limiting the rows a query returns. Each recipe asks a few questions and shows exactly what it will create. Then it creates that configuration in your organization.

A recipe can create policies, permissions, workflows, network rules, scenario monitors, hooks, or data loaders. A **Bundle** recipe creates several of these together.

The created items are ordinary configuration. You can edit or delete them later like anything else you create by hand.

## Use a Recipe

<Steps>
  <Step title="Find a recipe">
    Go to [Recipes](https://app.formal.ai/recipes). Filter by outcome (**AI Activity**, **Data Protection**, **Access Patterns**, or **Detection and Response**), by type, or by search.
  </Step>

  <Step title="Configure it">
    Click **Configure** on a recipe card. Answer each question, such as which Resources and which people the setup covers.
  </Step>

  <Step title="Review the plan">
    Click **Review and create**. The drawer lists every item the recipe will create. Nothing is created until you confirm.
  </Step>

  <Step title="Create the items">
    Click the button with the item count, such as **Create 2 items**. If some items fail, fix the cause and click **Retry remaining**.
  </Step>
</Steps>

**Verify:** The new items appear on their own pages, such as [Policies](https://app.formal.ai/policies) or [Network Rules](https://app.formal.ai/network-rules).

Creating items requires the same permissions as creating them by hand. Recipes marked **Coming Soon** aren't available yet.

## Available Recipes

| Recipe | Type | What it sets up |
| - | - | - |
| Block agent Git pushes | Bundle | Blocks pushes to protected GitHub repositories over SSH and HTTPS |
| Restrict Codex Desktop egress | Bundle | Allows LLM traffic, named MCP Resources, and ChatGPT sessions, and blocks direct web access and built-in search |
| Restrict Anthropic sign-ins | Bundle | Captures Anthropic LLM traffic and enforces your approved organization IDs |
| Set up the MCP gateway | Bundle | Serves MCP servers from a Connector so Claude, ChatGPT, and coding agents sign in with Formal |
| Prevent Merges by Cloud Agents | Bundle | Blocks cloud agents from merging pull requests while they can still prepare changes |
| Restrict Service Access to Approved People | Policy | Limits access to selected people, teams, and approved automation |
| Prevent Use of Personal AI Accounts | Policy | Blocks Anthropic sign-ins and API use outside your approved accounts |
| Block AI Agents | Policy | Blocks specific agents, unapproved agents, or agents running without human confirmation |
| Enforce Read-Only Access to Data | Policy | Lets people and agents read data while blocking changes and deletions |
| Limit the Rows a Query Returns | Policy | Caps query results so large exports need a deliberate exception |
| Require Sign-In Confirmation | Policy | Asks for multi-factor confirmation before sensitive sessions start |
| Restrict Agent Tool Access | Policy | Allows or blocks specific MCP tools for the people and agents who use them |
| Choose Who Can Manage Formal | Permission | Gives administrators full control, everyone else the view they need, and teams their areas |
| Notify People About Important Activity | Workflow | Sends policy blocks, successful sign-ins, or failed sign-ins to a Slack channel |
| Capture Application Activity | Network Rule | Captures the applications and destinations you choose, including subdomains and child processes |
| Route Services Through Formal | Network Rule | Sends selected service traffic to a Formal Resource for visibility and protection |

## Recipes for the Example Use Cases

Several [example use cases](/docs/guides/example-use-cases/block-agent-git-pushes) have a matching recipe. The guide explains each piece. The recipe creates the same configuration in a few clicks.

| Example use case | Recipe |
| - | - |
| [Block Agent Git Pushes](/docs/guides/example-use-cases/block-agent-git-pushes) | [Block agent Git pushes](https://app.formal.ai/recipes/block-agent-git-pushes) |
| [Restrict Codex Desktop Egress](/docs/guides/example-use-cases/restrict-codex-desktop-egress) | [Restrict Codex Desktop egress](https://app.formal.ai/recipes/restrict-codex-desktop-egress) |
| [Restrict Anthropic Sign-Ins](/docs/guides/example-use-cases/restrict-anthropic-sign-ins) | [Restrict Anthropic sign-ins](https://app.formal.ai/recipes/restrict-anthropic-sign-ins) |
| [Prevent Cloud Agents from Auto-Merging PRs](/docs/guides/example-use-cases/formal-endpoint-cloud-agents) | [Prevent Merges by Cloud Agents](https://app.formal.ai/recipes/cloud-agent-merges) |
| [MCP Gateway](/docs/guides/core-concepts/connectors/mcp-gateway) | [Set up the MCP gateway](https://app.formal.ai/recipes/mcp-gateway) |

## Next Steps

<CardGroup cols={2}>
  <Card title="Formal Agent" icon="sparkles" href="/docs/guides/getting-started/formal-agent">
    Ask the in-app assistant to draft configuration
  </Card>

  <Card title="Policies" icon="shield-check" href="/docs/guides/policies/introduction">
    Learn how policies work
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.