Rules and rule sets
A rule says what happens to an agent’s request. A rule set is the list of rules an agent follows. Admins and rule editors change rules; everyone else can read them.
Allow, Ask, Deny
Section titled “Allow, Ask, Deny”- Allow runs the action, and the audit log keeps it.
- Ask holds it until enough people from the rule’s team approve (see who approves).
- Deny never runs it; the agent hears it was denied by a rule.
A request that matches no rule is allowed and not recorded: the last row of every rule set, Everything else, is Allow.
When several rules match, the strictest decides, whatever their order: Deny, then Ask, then Allow. Every matching Ask rule needs its own approvals.
Write a rule
Section titled “Write a rule”- On Rules, click New rule.
- Pick a template, or Custom HTTP rule to write the method, host and path yourself:
- Method: one method, or Any method.
- Host: an exact host,
*.example.comfor every subdomain, or*for every host. - Path: a regular expression that must match the whole path;
/users/.*catches every path under/users/. Noset decodes and cleans the path first, so encoded or doubled slashes do not get around the rule.
- Pick the decision, and for Ask the team and how many must say yes.
- Try a request: paste a curl command, or a method and a URL. Noset shows how it reads the request and which rule decides. Nothing is sent.
- Read In plain words, then click Save rule.
The exact format of a rule: rule format.
Rule sets
Section titled “Rule sets”The Rule set control next to the title shows which rule set the page shows, with its version. Its menu lists every rule set, how many agents follow each, and New rule set, which starts empty or as a copy of the rule set on the page.
- Every agent follows the default rule set unless someone picks another one for it on the Agents page. Make it the default changes the default.
- Gates get a saved change on their next poll.
Versions and history
Section titled “Versions and history”Every save creates a new numbered version of the rule set. Old versions never change, and each one is in the audit log with its hash. History lists the versions, who saved each one, and what changed, marked Stricter or Looser.
Looser changes need a second admin
Section titled “Looser changes need a second admin”Making things safer is instant; making them looser needs a second look.
- Stricter, live at once: a new rule, Allow → Ask → Deny, more approvers.
- Looser, waits for a second admin: Ask or Deny → Allow, fewer approvers, changing or deleting the pattern of an existing rule, a looser default or agent rule set.
Until another admin approves, the version in force stays as it is. The change shows under Approvals › Admin changes and in the rule set’s History, where another admin clicks Approve change or Reject and the person who asked can withdraw it. See admin changes.