# Plugin Governance
Enterprise Registry
Fetch from npm or upload tgz; maintain names/descriptions delivered to client market.
Allowlist
Non-empty allowlist blocks out-of-list installs. Empty = unrestricted. Changes save and deploy instantly.
Handling Existing Violations
| Mode | Behavior |
|---|---|
| Enforce | Auto-uninstall (manifest + node_modules), full-screen restart prompt |
| Warn | Red banner in client market, no action |
| Log-only | No prompt, heartbeat record only |
Sighting History
Every out-of-list sighting is recorded: device, account, first/last seen, active/cleared status.