Skip to main content
Content and Resource Policies can transform data inline with redact or remove elements from a supported structured collection with filter. The strategy, path, predicate, and unavailable-data contracts are shared; the available data targets differ by policy family.

Redaction strategies

For partial, keepStart and keepEnd are integers from 0–256. maskCharacter is exactly one character and defaults to *. Non-string targets fail the transformation. hash.saltRef is an identifier used for domain separation, not a literal secret. Equal inputs within the same organization and salt reference produce equal output. fake.subtype accepts:

Structured paths

paths is optional unless the selected Resource target requires exact columns. Without it, Forge transforms the whole value available at a supported Content checkpoint or HTTP data target. With it, Forge transforms 1–64 selected values inside structured Content data, HTTP JSON, or a PostgreSQL result. Supported path syntax:
Paths are 3–512 characters and support:
  • the root $;
  • property segments such as .env;
  • zero-based array indexes such as [0].
Property names begin with a letter or underscore and may contain letters, numbers, _, or -. Wildcards, recursive descent, quoted keys, filters, slices, and negative indexes are not supported. When matching transformations overlap, Forge selects:

Filtering

For Content Policies, filter is valid only at post_tool. For Resource Policies, it is valid for an HTTP response body or PostgreSQL results. It removes elements from one structured collection while preserving the order of retained elements. Example:
If collectionPath or the predicate path cannot be evaluated, onUnavailable: "allow" returns the original result unchanged. onUnavailable: "block" converts the transformation failure into a blocked outcome. Forge does not coerce comparison types.

Resource transformations

Resource Policies add one required dataTarget for redact or filter: For HTTP, the shared path grammar addresses decoded JSON. Forge accepts at most 32 KiB of decoded body data and transforms it before forwarding any targeted body. A matching enforcing policy fails closed when the body is missing, malformed, compressed, oversized, streaming, or not JSON. It does not return the original data because a transformation could not run. For a successfully decoded JSON value, onUnavailable still controls a missing filter collection or predicate path; it cannot override the body-format and size checks. For PostgreSQL redaction, each path names an exact result column, such as $.email. Paths are required. For PostgreSQL filtering, collectionPath is $.rows, and removeWhere.path names a column relative to each row. Filtering runs before redaction. Forge preserves NULL and adjusts delivered SELECT and FETCH row counts after filtering. nullify works with text and binary fields; comparisons and all other redaction strategies require a text-compatible field format. MySQL uses the same $.column paths and $.rows filter collection. Text results support safe scalar comparisons and all shared textual strategies. Binary results support nullification for safely framed values and textual strategies for character columns. Missing, duplicate, malformed, or incompatible targeted columns fail closed before the original value is sent. COPY results, missing or ambiguous column descriptions, malformed messages, and incompatible value formats fail closed before an original targeted value is released. Forge does not retain HTTP bodies or PostgreSQL/MySQL row values in Activity or backtests.