Concepts
Policies, monitor and enforce
Policies decide what your agents may do. Every policy starts in monitor mode and only blocks traffic after you promote it to enforce.
A policy is a rule the gateway applies to your agents' requests. For example: "Block requests that contain credit card numbers", "Only production agents may use this model" or "Hold requests to delete data for a person to approve".
What a policy can decide
For each request it applies to, a policy returns one decision:
| Decision | What happens in enforce mode |
|---|---|
| Allow | The request goes through. |
| Deny | The request is blocked and the agent receives an error that names the policy. |
| Require approval | The request waits until a person approves or denies it. |
| Redact | Sensitive content is removed before the request reaches the model. |
Monitor, enforce and off
Every policy has a mode:
- Monitor: the policy runs on real traffic and records what it would have decided, but never changes a request. Every new policy starts here.
- Enforce: the policy's decisions take effect. Denied requests are blocked and approvals are required.
- Off: the policy does not run.
Monitor mode lets you see the effect of a rule on real traffic before it can affect anyone. In AI Governance → Activity → Audit log, a request that a monitored policy would have blocked shows as Would deny, and it still went through.
Promoting a policy to enforce
Once you trust a policy, you promote it. Clovie asks for evidence first:
- Run a simulation: in AI Governance → Policies → My policies, select Simulate on the policy. Clovie replays the last 7 days of your traffic through it and shows how many requests it would have allowed, denied or sent for approval.
- Check the results: if the policy would block traffic you did not expect, edit it and simulate again.
- Promote: select Promote to enforce and confirm. The simulation must be for the current version of the policy and less than 24 hours old.
Only administrators and policy administrators can promote a policy. If someone later changes what an enforced policy checks or who it applies to, it goes back to monitor mode until it is simulated and promoted again.
Who a policy applies to
A policy's Scope decides which agents it covers:
- Organization: every agent.
- Specific teams: agents owned by the teams you choose.
- Specific agents: only the agents you name.
- Matching agents: agents that match conditions you set, such as their environment.
You can exclude individual agents from a wider policy. For a temporary exception, an agent owner can request an exemption, which a policy administrator other than the requester must approve, and which ends automatically on its expiry date.
Where policies come from
- Policy Hub has ready-made packs for common needs, such as data privacy, security baselines and regulatory frameworks. Packs install in monitor mode.
- My Policies is where you create your own policies in the policy editor, test them against a sample request, and manage every policy you have.
- Import from document turns a written policy, such as an AI usage policy, into a draft policy that installs in monitor mode for you to review.
Approvals
When an enforced policy requires approval, the request appears in AI Governance → Policies → Approvals. An approver sees the agent, the model, the policy and the request, and selects Approve or Deny. An approval allows that one request to be retried; it does not change the policy.
Related
- Gateway: where policies are applied.
- Budgets and price books: spending limits use the same monitor-then-enforce approach.