A new research paper proposes deontic policies to manage the obligations and prohibitions of autonomous agents. Current policy engines fail to handle complex enterprise rules, such as mandatory CISO notifications after specific actions. This framework allows developers to define rule precedence and conditional waivers. It provides a formal structure for constraining agents that manipulate data and install software.