Skip to main content
An action is the typed consequence of a matching policy. Match logic returns a boolean result; it cannot invent or execute an action.

Action reference

At an observe-only source, Forge can record a policy hit but cannot retroactively alter a completed action.

Resource compatibility

Resource Policies use the same outcome aggregation, precedence, policy messages, exception handling, revision binding, and activity evidence as other families. The actions exposed for a Resource are capability-gated: Resource redact and filter require a compatible dataTarget. Resource approval requires an approval mode and cannot depend on response or result data. Invalid combinations are rejected for native conditions and Rego-backed policies. For one operation, Forge resolves block or approval before mutation. Otherwise filters compose before redactions. Overlapping redactions use the strategy precedence below. Monitor-mode transformations and approvals are recorded but never enter the applied action plan.

Content compatibility

Invalid action/checkpoint combinations are rejected when the policy is saved. See Redaction for transformation inputs and outputs.

Approvals

Content approval policies run before tool execution. Their approval object accepts: Access approval policies require: Resource approval uses the same two modes. Its grant expires after ten minutes, can be used once, and permits only an identical retry of the connection, request, or command that created it. Forge does not hold an HTTP stream, database connection, or transaction while approval is pending. Approval grants are bound to the policy ID and immutable revision. A grant for an older revision does not authorize a changed policy.

Nudges

A nudge does not interrupt the operation. Supported gateway and endpoint adapters insert guidance into the next supported model request. If a source cannot inject context, Forge retains the hit without modifying the completed operation. nudge is invalid at response because there is no later model step to receive the guidance.

Multiple matches

Forge retains all matching hits and chooses the strongest action:
An allow policy therefore cannot cancel a block from another policy. Overlapping redactions use their own strategy precedence, documented under Redaction.

Defaults

MCP Registry and Skill Registry access rules are managed from the Registry’s MCPs and Skills views, then evaluated through their policy-backed access controls. See MCP requests and Skill requests for the related review workflows.

Failures

A native condition that depends on unavailable facts does not match and emits a fields_unavailable diagnostic. A Rego policy that is malformed, times out, returns undefined, or produces invalid output fails closed with block. Every hit includes the policy ID and immutable revision. Native evaluation can also report matched exceptions and unavailable fields; Rego can return a stable reason code and bounded evidence.