Skip to content

Policies

Policies are rules that override or tighten the risk engine. You can edit them in the app, or manage them as code with the CLI (vulnify policies pull, vulnify policies apply, and vulnify test). The file format is on Policy files. When no policy matches, the decision comes from the risk engine score.

ALLOW on a policy is an explicit override of the risk engine. A policy can also force REVIEW or BLOCK.

The decision object includes the matching policy when there is one:

{ "policy": { "id": "pol_id", "name": "Block large external exports" } }

policy is null when the risk engine decided and no policy matched.

Each policy has a mode:

Mode Behavior
ENFORCE The policy decision is enforced.
MONITOR The policy is observed. Monitor mode records what would have happened.

Organization-level monitor mode is separate: while it is on, Vulnify records what would have been blocked or reviewed and finalDecision is ALLOW. evaluatedDecision still shows the enforced outcome. See Decisions.

The app’s policy templates include rules marked monitor-only, as a way to see what would be blocked before you enforce them.

On a policy file, spec.action is the family (READ, WRITE, DELETE, EXPORT, or ANY). The event action (READ_DATA, WRITE_DATA, DELETE_DATA, EXPORT_DATA, SEND_EMAIL) goes in the condition. See Policy files.

A rule matches on any combination of:

  • Action (READ_DATA, WRITE_DATA, DELETE_DATA, EXPORT_DATA, SEND_EMAIL, or any)
  • Resource, or a resource type
  • Destination: any, external only, internal only, or “destination contains”
  • Minimum and maximum recordsAffected
  • Minimum risk score
  • The resource holds sensitive data
  • Outside business hours, defined in the app as Monday–Friday 09:00–18:00 in the organization time zone
  • A list of specific agents

Conditions can be grouped. All of means every condition in the group must match. Any of means at least one must match.

When the policy decision is REVIEW, the rule lists who can approve it. Roles in the app are owner, admin, and member. See Reviews.

The app can dry-run a draft policy against an example action, including optional content, and can replay recent history to show how many events would change. The CLI can dry-run and test the same rules from YAML. vulnify policies apply --dry-run needs an org-wide LIVE key. vulnify test writes no security event. The file shape is on Policy files.