> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies.md).

# CI/CD Policies

CI/CD policies define how a system should respond to threats in pipelines. It includes conditions that trigger the policy, the scope of its application, and the actions to be taken when these conditions are met. When a policy detects a threat, it generates an issue for remediation.

Cortex Cloud provides out-of-the-box CI/CD policies. In addition, you can create custom policies to tailor it to your specific business or infrastructure requirements. Out-of-the-box policies cannot be modified directly. However, you can create a custom policy by cloning the existing one. This allows you to make changes to the original policy according to your requirements. Refer to [Manage CI/CD policies](/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/manage-cicd-policies.md) for more information.

### Learn more

* [CI/CD policies user roles and permissions](/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/cicd-policies-user-roles-and-permissions.md)
* [CI/CD policies inventory](/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/cicd-policies-inventory.md)
* [Create CI/CD configuration policies](/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/create-cicd-configuration-policies.md)
* [Manage CI/CD policies](/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies/manage-cicd-policies.md)

{% hint style="info" %}

### Tip

For Cortex Cloud Code policies, refer to [Unified Application Security policies](/application-security/application-security-posture-management-aspm/unified-application-security-policies.md).
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/governance-and-enforcement/cicd-policies.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
