Author and Roll Out a Policy
Pavri policies control runtime actions for selected agents. Start in an observe-oriented rollout stage whenever you are introducing a new control or changing a policy with a broad blast radius.
Create a policy
- Open Policies and select Author Policy.
- Choose a policy family or start with a template. Pavri includes templates for tool allowlists, domain allowlists, cost budgets, rate limits, and PII detection.
- Give the policy a clear name and an operator-facing objective.
- Select the response: alert, block, throttle, quarantine, redact, or terminate. Choose the least disruptive response that meets your security objective.
- Configure the controls and add only narrowly justified exceptions.
- Assign the policy directly or target it with fleet attributes. Review the resulting selected-agent list before saving.
Review impact and roll out
- Review the compiled rule blocks and policy snapshot.
- Read the predicted impact, including assignment scope and validation warnings.
- Create the policy in a non-enforcing rollout stage when testing a new control.
- Monitor policy decisions, sessions, alerts, and agent health after each rollout expansion.
- Use the policy detail and rollout views to change scope, narrow an exception, or return to a less disruptive stage when the policy causes an unexpected outcome.
Evidence and recovery
Policy decisions appear in session evidence and activity. Preserve those records when tuning a rule or responding to an incident. If an enforcement change blocks a critical workflow, reduce the rollout stage or scope first, then investigate the matching policy decision before broadening an exception.
See Policy Overview for enforcement modes and fail-open/fail-closed behavior.