Skip to content

Rules from templates

A template turns “Google Drive → delete → Ask” into the HTTP rules that catch it. You pick in plain words; Noset writes the rules.

Template What it covers
Delete anywhere any DELETE request, on any host
Cloud Storage and S3 deleting objects or buckets, or changing who can read them
GitHub deleting repositories or branches, merging, pushing, changing protection
Google Drive deleting, trashing or sharing files
Kubernetes deleting, changing, creating or exec in a namespace
Stripe refunds, payouts and transfers; deletes and cancels; prices

Templates are built from each API’s published description and checked by hand; Delete anywhere is written by hand.

  1. On Rules, click New rule, then a template.
  2. Pick the actions the agent may not do on its own. Each action is a group of the API’s operations. Reading always runs.
  3. Fill in the scope the template asks for, such as namespaces, buckets or repositories. Empty covers every one.
  4. Pick the decision, and for Ask the team and how many must say yes.
  5. Click Save rule.

A template rule is one rule, so it needs one approval, even when it covers several operations.

Ask for unknown changes is on by default. When the API adds an operation the template does not know yet, a change through it still needs approval, so nothing slips through. Operations the template knows are not asked by the safety net; the ones you picked have the rule above. Pick who approves unknown changes below it.

When Noset ships a newer version of a template, it writes the rules made from it again, as a new version of the rule set. Your rules never change on their own between versions.

  • Stricter updates (the template covers more) go live at once, and the rules’ approver teams are told.
  • Looser updates (the template could cover less) wait for an admin; with more than one admin, any admin approves a version Noset wrote.

Rules › Template updates lists every update with what it changes. A rule whose template has a newer version shows Update to and the version.

Apply stricter template updates at once is on by default (Settings › Organization, and on the Template updates page). Switched off, every template update waits for an admin. Switching it off is looser, so with another admin it waits for them.