Skip to content

Actions

A check describes one action the agent is about to take. The SDKs type these action names:

action Typical use
READ_DATA Read records from a resource.
WRITE_DATA Create or update records.
DELETE_DATA Delete records.
EXPORT_DATA Export records, including to an external destination.
SEND_EMAIL Send email.

These are the values both SDKs send. Register the resource in the app under the same name you pass as resource, or pass resourceId.

destination is optional. The SDKs type three values:

Value Meaning in the product samples
INTERNAL Stays inside the organization. The SDK examples use this when the address is on the company domain.
EXTERNAL_EMAIL Leaves via email.
EXTERNAL_API Leaves via an external API.

Policies can match any destination, external only, internal only, or a destination string that contains a given fragment.

recordsAffected (Python: records_affected) is the number of records the action would touch. Policies can require a minimum or maximum. The risk engine and anomaly detection use the count as metadata. It is a count, not the records.

Resources are registered in the app, the same way agents are. A resource can be marked as holding sensitive data. A policy condition can match only when the resource is sensitive.

An unknown resource is rejected the same way an unknown agent is: the SDK raises, and fail-open does not hide it.

content is an optional string the server scans for sensitive data (for example CPF, card numbers, or secrets). The maximum length is 100000 characters. Findings return on the decision as dlpFindings, with lgpdCategories derived from them. The content is scanned in memory and not stored. The whole JSON body must also be at most 200 KB. A larger body is HTTP 413, which is a client error and is never fail-open. See Risk engine and Errors.

Send content only when you are allowed to. The check does not need content for an allow, review, or block decision on metadata alone.