Clovie Docs

Concepts

Policies, monitor and enforce

Policies decide what your agents may do. Every policy starts in monitor mode and only blocks traffic after you promote it to enforce.

A policy is a rule the gateway applies to your agents' requests. For example: "Block requests that contain credit card numbers", "Only production agents may use this model" or "Hold requests to delete data for a person to approve".

What a policy can decide

For each request it applies to, a policy returns one decision:

DecisionWhat happens in enforce mode
AllowThe request goes through.
DenyThe request is blocked and the agent receives an error that names the policy.
Require approvalThe request waits until a person approves or denies it.
RedactSensitive content is removed before the request reaches the model.

Monitor, enforce and off

Every policy has a mode:

  • Monitor: the policy runs on real traffic and records what it would have decided, but never changes a request. Every new policy starts here.
  • Enforce: the policy's decisions take effect. Denied requests are blocked and approvals are required.
  • Off: the policy does not run.

Monitor mode lets you see the effect of a rule on real traffic before it can affect anyone. In AI Governance → Activity → Audit log, a request that a monitored policy would have blocked shows as Would deny, and it still went through.

Promoting a policy to enforce

Once you trust a policy, you promote it. Clovie asks for evidence first:

  1. Run a simulation: in AI Governance → Policies → My policies, select Simulate on the policy. Clovie replays the last 7 days of your traffic through it and shows how many requests it would have allowed, denied or sent for approval.
  2. Check the results: if the policy would block traffic you did not expect, edit it and simulate again.
  3. Promote: select Promote to enforce and confirm. The simulation must be for the current version of the policy and less than 24 hours old.

Only administrators and policy administrators can promote a policy. If someone later changes what an enforced policy checks or who it applies to, it goes back to monitor mode until it is simulated and promoted again.

Who a policy applies to

A policy's Scope decides which agents it covers:

  • Organization: every agent.
  • Specific teams: agents owned by the teams you choose.
  • Specific agents: only the agents you name.
  • Matching agents: agents that match conditions you set, such as their environment.

You can exclude individual agents from a wider policy. For a temporary exception, an agent owner can request an exemption, which a policy administrator other than the requester must approve, and which ends automatically on its expiry date.

Where policies come from

  • Policy Hub has ready-made packs for common needs, such as data privacy, security baselines and regulatory frameworks. Packs install in monitor mode.
  • My Policies is where you create your own policies in the policy editor, test them against a sample request, and manage every policy you have.
  • Import from document turns a written policy, such as an AI usage policy, into a draft policy that installs in monitor mode for you to review.

Approvals

When an enforced policy requires approval, the request appears in AI Governance → Policies → Approvals. An approver sees the agent, the model, the policy and the request, and selects Approve or Deny. An approval allows that one request to be retried; it does not change the policy.

On this page