Policies

Policies define conditions that trigger automated responses, from alerts to blocking an action entirely, and they run server-side on every signed action for real-time control over what your agents can do. Use the built-in engine or bring your own rules. Either way Asqav signs the outcome into a tamper-evident receipt, recorded by a party that is not the agent's operator.

Creating Policies

Create a policy with a name, condition, and action:

bash
# Create a rate limit policy
curl -X POST https://api.asqav.com/api/v1/policies \
  -H "X-API-Key: sk_live_your_key" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "api-rate-limit",
    "description": "Limit API calls to 100 per minute",
    "action_pattern": "api:*",
    "conditions": {"rate_limit": "100/minute"},
    "action": "block_and_alert",
    "severity": "high"
  }'

# Response includes the policy id and active flag
{"id": "pol_abc123", "name": "api-rate-limit", "is_active": true, ...}

Policy Conditions

Every policy matches actions by action_pattern, a glob matched against the action_type (for example api:* or data:delete:*; * matches everything). The optional conditions object narrows the trigger further:

Condition key Value Format Description
rate_limit {count}/{period} Triggers when an agent exceeds the action rate. Periods: minute, hour, day
payload_contains Plain text string Triggers when action metadata contains the specified string
payload_regex Regular expression Triggers when action metadata matches the regex pattern
time_window HH:MM-HH:MM Triggers when actions occur outside the allowed time window (UTC)

payload_contains and payload_regex inspect the action context, so they cannot evaluate on hash-only signs: the payload never reaches the API. Rate limits and time windows still evaluate on every sign. When a hash-only sign matches a policy that carries payload conditions, the receipt's controls_evaluated.policy entry records the limitation with payload_conditions_not_evaluated: true. See Control Attestation.

For action_pattern, the SDK resolves semantic names like sql-destructive or file-write to their glob equivalents with asqav.resolve_pattern("sql-destructive") (returns data:delete:*). See Enforcement for the full list of built-in patterns.

bash
# Block destructive SQL (glob from asqav.resolve_pattern("sql-destructive"))
curl -X POST https://api.asqav.com/api/v1/policies \
  -H "X-API-Key: sk_live_your_key" \
  -H "Content-Type: application/json" \
  -d '{"name": "block-destructive-sql", "action_pattern": "data:delete:*", "action": "block"}'

# Block actions containing sensitive keywords
curl -X POST https://api.asqav.com/api/v1/policies \
  -H "X-API-Key: sk_live_your_key" \
  -H "Content-Type: application/json" \
  -d '{"name": "block-delete-operations", "conditions": {"payload_contains": "DROP TABLE"}, "action": "block"}'

# Regex match for credit card numbers
curl -X POST https://api.asqav.com/api/v1/policies \
  -H "X-API-Key: sk_live_your_key" \
  -H "Content-Type: application/json" \
  -d '{"name": "detect-credit-cards", "conditions": {"payload_regex": "\\b\\d{4}[- ]?\\d{4}[- ]?\\d{4}[- ]?\\d{4}\\b"}, "action": "alert"}'

Policy Actions

Actions define what happens when a condition is triggered:

Action Behavior Agent Impact
alert Logs an alert, action proceeds None - agent continues normally
block Rejects the action silently Action fails, agent remains active
block_and_alert Rejects the action and logs an alert Action fails, alert created
suspend_agent Suspends the agent immediately All future actions rejected until unsuspended

Listing Policies

bash
# List all policies
curl https://api.asqav.com/api/v1/policies \
  -H "X-API-Key: sk_live_your_key"

# Response (truncated)
[
  {
    "id": "pol_abc123",
    "name": "api-rate-limit",
    "action_pattern": "api:*",
    "conditions": {"rate_limit": "100/minute"},
    "action": "block_and_alert",
    "is_active": true,
    "violation_count": 0
  }
]

Toggling Policies

Enable or disable policies without deleting them:

bash
# Toggle a policy between active and inactive
curl -X POST https://api.asqav.com/api/v1/policies/pol_abc123/toggle \
  -H "X-API-Key: sk_live_your_key"

# Check current state
curl https://api.asqav.com/api/v1/policies/pol_abc123 \
  -H "X-API-Key: sk_live_your_key"
Tip

Start with the alert action to monitor policy triggers before switching to block. This lets you tune conditions without disrupting agent operations.

Auto-Remediation

Agents are automatically suspended after exceeding a violation threshold. Suspension runs on all plans. Automatic quarantine on critical alerts is available on Enterprise.

You can configure the suspension threshold and time window:

bash
# Get current config
curl https://api.asqav.com/api/v1/remediation/config

# Update threshold
curl -X PUT https://api.asqav.com/api/v1/remediation/config \
  -d '{"auto_suspend_threshold": 10, "auto_suspend_window_seconds": 7200}'
SettingDefaultRangeDescription
auto_suspend_threshold51-100Violations before auto-suspend
auto_suspend_window_seconds360060-86400Rolling window for counting violations

Per-action save policy

The action_type_policies table lets a regulated org set retention shape per action_type. A wire-transfer action can carry the full payload for seven years while support-ticket replies are stored hash-only for ninety days, in the same organization, without a separate cloud install.

The default behaviour, when no row matches a given action_type, is the existing org-level retention mode. The cloud applies the policy at sign time, regardless of what the SDK requested.

save_modeEffect at sign time
fullRaw payload and metadata persisted, subject to the org retention window.
hashRaw payload dropped at sign time. Only canonical bytes hash and the signature persist.
sql
INSERT INTO action_type_policies (organization_id, action_type, save_mode, retention_seconds)
VALUES ('org_abc123', 'support.ticket.reply', 'hash', 7776000);

Manage policies from the terminal with asqav policies (list, create, delete).