Skip to content

Authors a containment rule.

POST
/v1/m/governance/guardian/rules
curl --request POST \
--url https://example.com/v1/m/governance/guardian/rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "action": "example", "agent_tier": "example", "enabled": true, "match_kinds": "example", "min_severity": "example", "mode": "example", "name": "example", "note": "example" }'

Authors a containment rule. Admin-tier (authoring auto-containment is enforcement-posture authoring); self-audited.

X-Olivares-Tenant
string format: uuid

Target tenant id; required when the principal can act in more than one tenant.

Media type application/json
object
action
required

Case-insensitive after trimming: stop_agent, quarantine_nhi, or stop_estate.

string
agent_tier
Any of:

Case-insensitive after trimming: low, medium, high, critical, or empty for any.

string
enabled
Any of:

Defaults to true when absent or null.

boolean
match_kinds
Any of:

Comma-separated finding kinds, capped at 4096 bytes; guardian self-finding prefixes are forbidden.

string
min_severity
Any of:

Case-insensitive after trimming: info, low, medium, high, or critical; empty defaults to high.

string
mode
required

Case-insensitive after trimming: auto or approval.

string
name
required

Trimmed rule name capped at 128 bytes.

string
/.*\S.*/
note
Any of:

Capped at 4096 bytes.

string
Example generated
{
"action": "example",
"agent_tier": "example",
"enabled": true,
"match_kinds": "example",
"min_severity": "example",
"mode": "example",
"name": "example",
"note": "example"
}

OK

Media type application/json
object
Example generated
{}

Bad request

Media type application/json
object
Example generated
{}

Unauthenticated

Media type application/json
object
Example generated
{}

Forbidden

Media type application/json
object
Example generated
{}

Not found

Media type application/json
object
Example generated
{}

Conflict / setup required

Media type application/json
object
Example generated
{}

Rate limited

Media type application/json
object
Example generated
{}