Skip to content

Test a rule

A test checks the path of an approval before an agent needs it: who is asked, where they are reached, and that they can answer. Nothing runs.

  1. On Rules, open an Ask rule.
  2. Click Run a test, then Send a test in Test the approval path.
  3. Watch who it reached and where, and who answered.
  4. Click End the test when you have seen enough, or let it run out.

Admins and rule editors run tests. The person who started a test, an admin or a rule editor can end it early.

The same request a real agent would make, with the same team, count, channels and four-eyes rule, marked TEST · nothing will run. It shows a made-up request the rule matches, for example DELETE customer.api.kestrel.dev/users/0000. When no simple request matches the rule, it shows what the rule matches instead.

Approvers answer as they would a real request: in the web app, Slack or Teams. The rule’s count makes it approved; one deny makes it denied.

  • Everyone it reached, and in which channels.
  • Who answered, and how.
  • Not asked: with four eyes on, whoever starts the test is not asked, as whoever starts an agent is not asked about its requests.
  • A warning when Slack is set up but no Slack account uses an approver’s email: that person is reached in the web inbox only, and real requests do the same.
  • A test runs at most 10 minutes, then it expires.
  • A rule can be tested once every 10 minutes, counted from the start of its last test.
  • A test never makes a permit, has no agent and no gate, and is not sent to webhooks.

The audit log records the test’s start (who started it, the rule, who was asked and who was not), each answer, and how it ended. These records are marked Test · nothing ran. A test never writes a real approval, denial, expiry or permit.