Enforcement Actions and Status
Use this reference to distinguish a configured rule from protection confirmed by a sensor. For the activation workflow, see Runtime Enforcement.
Requirements
Creating, editing, enabling, or disabling enforcement requires Operator or Admin access to the selected targets. Each target must support the policy's requested action.
Start with one non-critical sensor. Review recent matching activity and test the expected result before expanding the scope.
What an action means
| Action | Effect |
|---|---|
| Observe | Records matching activity without blocking the operation or terminating the process. |
| Deny an operation | Returns an error for the matched operation when the selected protection and host support denial. |
| Terminate a process | Sends a termination signal to the matching process. This is not a permission-denied response. |
The policy inspector shows the configured action. Custom policies may use Post for observation, Sigkill or Signal for termination, or Override for a supported denial action.
Not every host or policy supports every action. Review validation messages and the sensor's delivery result. A saved policy is not proof that it is loaded.
Review activation
The activation dialog identifies the policy, action, targets, and recent potential impact. It also shows exceptions and workload warnings when applicable.
- Confirm the intended sensors or groups.
- Review processes that matched during the preview period.
- Check exclusions and the effect of the action.
- Enter ENFORCE when requested, then activate the policy.
- Open delivery details and confirm each intended sensor has accepted it.
No preview matches means no matching evidence was found in that window. It does not establish that future application activity will be unaffected.
Confirm delivery
| Status | Next step |
|---|---|
| Applying | Check whether the target sensors are online and have reported a policy result. |
| Active | Review per-sensor confirmation before treating the whole scope as protected. |
| Partially active | Inspect which sensors accepted the rule and which reported a failure. |
| Rejected | Read the sensor error, correct the policy or compatibility issue, then reapply. |
| Disabled | Confirm removal on the intended sensors before closing the change. |
Offline sensors cannot confirm a change until they reconnect. Do not assume a fleet-wide action completed everywhere from the rule's enabled setting alone.
Inspect protection on a host
Open Sensors > Fleet, select a sensor, then open Enforcement. Use Inspect policy on an active rule to read its configured policy content.
To change the rule, open it in Runtime Blocks. An edit can affect every target in the rule's scope, not only the sensor from which you opened it.
Recover from an unintended block
- Disable the affected rule in Respond > Runtime Blocks.
- Confirm the change on the affected sensors.
- Check that the application has recovered.
- Inspect the matched process and operation.
- Narrow the rule or add an appropriate exception before testing again.
A disabled rule remains available for review. Disabling does not restart processes that were already terminated.