DocslothPolicies
checking session

Policies

Policies displays real server state with a next action, not placeholder statistics.

Surface contract

Primary object: the fleet rules and approval conditions the server holds, each with its contract revision.

Actions

  • Preview changeThe workbench sends the proposed rule set and the edited sample request to POST /v1/policies/{id}/preview and renders the server’s decision — effect, matched rule index and reason. Nothing is evaluated in the browser.
  • EnforceEnforcement is the revision the engine reads: Enforce sends PUT /v1/policies/{id}, raising the contract revision, and New policy / rule edits use the same contracts (POST/PUT /v1/policies).
  • RollbackThe revision list comes from GET /v1/policies/{id}/revisions; Roll back confirms in a dialog, sends POST /v1/policies/{id}/rollback with the chosen revision, and shows the new revision the server reports.
Required states and how this surface reaches them
loading
the session probe and each list show Loading… until the control plane answers.
ready
the server’s own records render as returned; the primary object is named before its details.
empty
no policy row exists; New policy creates one through POST /v1/policies with an empty rule set that is then edited server-side.
error
a malformed or non-array rules payload is refused with the server’s own detail; the typed name is preserved in the dialog, and a refused preview keeps the API detail without inventing a decision.
offline
no control plane is reachable; nothing is rendered rather than invented.
permission_denied
a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
not_configured
a preview or rollback with no reachable control plane answers 503 or an offline note; no decision and no revision is shown in its place.
budget_paused
a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
requires_approval
policies can require owner approval for changes; a refusal is shown with its detail and is never bypassed.

Scope: workspace membership (owner/admin for changes). Rules are stored server-side and consumed by the engine; the page never evaluates a rule in the browser and never claims a change the server did not record.

Policy preview

Edit the proposed rule set and the sample request; the control plane evaluates them (POST /v1/policies/{id}/preview) and its decision is shown below. The browser evaluates nothing.

Loading…

Policy revisions

Immutable revisions the control plane stores for this policy. Rolling back writes a new revision from the chosen one.

Loading…

Roll back policy

Policies

checking

Loading…

Audit trail

checking

Loading…

Rows come from the authenticated control plane; this page never renders placeholder records. Actions report the server's own response, including refusals.