Policies
Policies displays real server state with a next action, not placeholder statistics.
Surface contract
Primary object: the fleet rules and approval conditions the server holds, each with its contract revision.
Actions
- Preview changeThe workbench sends the proposed rule set and the edited sample request to POST /v1/policies/{id}/preview and renders the server’s decision — effect, matched rule index and reason. Nothing is evaluated in the browser.
- EnforceEnforcement is the revision the engine reads: Enforce sends PUT /v1/policies/{id}, raising the contract revision, and New policy / rule edits use the same contracts (POST/PUT /v1/policies).
- RollbackThe revision list comes from GET /v1/policies/{id}/revisions; Roll back confirms in a dialog, sends POST /v1/policies/{id}/rollback with the chosen revision, and shows the new revision the server reports.
Required states and how this surface reaches them
- loading
- the session probe and each list show Loading… until the control plane answers.
- ready
- the server’s own records render as returned; the primary object is named before its details.
- empty
- no policy row exists; New policy creates one through POST /v1/policies with an empty rule set that is then edited server-side.
- error
- a malformed or non-array rules payload is refused with the server’s own detail; the typed name is preserved in the dialog, and a refused preview keeps the API detail without inventing a decision.
- offline
- no control plane is reachable; nothing is rendered rather than invented.
- permission_denied
- a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
- not_configured
- a preview or rollback with no reachable control plane answers 503 or an offline note; no decision and no revision is shown in its place.
- budget_paused
- a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
- requires_approval
- policies can require owner approval for changes; a refusal is shown with its detail and is never bypassed.
Scope: workspace membership (owner/admin for changes). Rules are stored server-side and consumed by the engine; the page never evaluates a rule in the browser and never claims a change the server did not record.
Policy preview
Edit the proposed rule set and the sample request; the control plane evaluates them (POST /v1/policies/{id}/preview) and its decision is shown below. The browser evaluates nothing.
Loading…
Policy revisions
Immutable revisions the control plane stores for this policy. Rolling back writes a new revision from the chosen one.
Loading…
Policies
checkingLoading…
Audit trail
checkingLoading…
Rows come from the authenticated control plane; this page never renders placeholder records. Actions report the server's own response, including refusals.