Skip to main content

Author and Roll Out a Policy

Pavri policies control runtime actions for selected agents. Start in an observe-oriented rollout stage whenever you are introducing a new control or changing a policy with a broad blast radius.

Create a policy

  1. Open Policies and select Author Policy.
  2. Choose a policy family or start with a template. Pavri includes templates for tool allowlists, domain allowlists, cost budgets, rate limits, and PII detection.
  3. Give the policy a clear name and an operator-facing objective.
  4. Select the response: alert, block, throttle, quarantine, redact, or terminate. Choose the least disruptive response that meets your security objective.
  5. Configure the controls and add only narrowly justified exceptions.
  6. Assign the policy directly or target it with fleet attributes. Review the resulting selected-agent list before saving.

Review impact and roll out

  1. Review the compiled rule blocks and policy snapshot.
  2. Read the predicted impact, including assignment scope and validation warnings.
  3. Create the policy in a non-enforcing rollout stage when testing a new control.
  4. Monitor policy decisions, sessions, alerts, and agent health after each rollout expansion.
  5. Use the policy detail and rollout views to change scope, narrow an exception, or return to a less disruptive stage when the policy causes an unexpected outcome.

Evidence and recovery

Policy decisions appear in session evidence and activity. Preserve those records when tuning a rule or responding to an incident. If an enforcement change blocks a critical workflow, reduce the rollout stage or scope first, then investigate the matching policy decision before broadening an exception.

See Policy Overview for enforcement modes and fail-open/fail-closed behavior.