[Docs index](/docs.md) / [Tool Policies](/docs/tool-policies/overview.md) / Managing the Rule List

---

# Managing the Rule List

This guide covers the ongoing work of keeping tool policies in shape: reading the list, changing the order, setting the workspace default, and reviewing what was blocked.

## Before you begin

- You must be a workspace admin to change anything. Members can view the list.
- Open **Permissions** and select the **Tool Policies** tab.

## Who can do what

| Role | What it allows |
|------|----------------|
| Member | View the rules and the workspace default |
| Admin | Create, edit, reorder, disable, and delete rules. Change the workspace default. Use the simulator. Start a rule from Tool History. |

## Reading the list

Each row is one rule. Rules are read from the top.

| Column | What it shows |
|--------|---------------|
| # | The rule's position. Lower numbers are read first. |
| Action | **Deny** or **Allow** |
| Target | The tool pack and tool, or a pattern. `*` means every tool. |
| Applies to | Who the rule covers |
| Conditions | A summary of the conditions, or the reason when there are none |
| Blocked 7d | How many calls this rule blocked in the last seven days |

Click a row to expand it. The expanded row shows every condition in full, the reason, what the AI is told when a call is blocked, the sources the rule is limited to, and when it was last changed.

Use the search field to find rules by tool, person, or reason. Use **All**, **Deny**, **Allow**, and **Disabled** to filter the list.

## Changing the order

The first rule that matches a call decides it, so order changes what happens.

Click the **More** menu at the end of a row and choose **Move up** or **Move down**. The option is unavailable when the rule is already at that end of the list.

To move a rule a long way, open it with **Edit** and use **Placement** to put it at the top, at the bottom, or after a specific rule.

A common arrangement, from top to bottom:

1. Narrow exceptions that allow something for a specific group or agent.
2. Rules that block specific tools or values.
3. Broad rules that block a whole tool pack or pattern.

## Setting the workspace default

The **Default** row at the bottom of the list decides any call that no rule matched.

| Default | What it means |
|---------|---------------|
| Allow | Everything is permitted unless a rule blocks it. This is the starting setting. |
| Deny | Everything is blocked unless a rule allows it. |

Changing the default to **Deny** blocks every tool in the workspace that does not have an allow rule, for everyone, including admins and running agents. Before you switch:

1. Add allow rules for the tools your team and agents need.
2. Check them in the [simulator](testing-rules-with-the-simulator.md) for a few different people.
3. Switch the default at a quiet time, and watch Tool History for blocked calls.

## Turning a rule off without deleting it

Open the **More** menu and choose **Disable**. The rule stays in the list, keeps its position, and stops applying. Choose **Enable** to turn it back on.

Use this to pause a rule while you investigate, or to prepare a rule before you want it in effect.

## Editing and deleting

- To change a rule, open the **More** menu and choose **Edit**, or expand the row and click **Edit**.
- To remove a rule, open the **More** menu and choose **Delete**. Deleting cannot be undone. Calls the rule blocked in the past stay in Tool History, with the reason recorded at the time.

## Reviewing blocked calls

Open **Tool History** and select the **Blocked** filter. Blocked calls have a blue marker.

Click a call to see **Execution Details**. Under **Blocked by policy** you will find the reason on the rule that stopped the call and the message the AI was given. The values the call was made with are shown below.

Blocked calls count toward the total number of executions. They do not count against the success rate, because the tool never ran.

Review blocked calls after adding a rule. A high count on a new rule can mean it is catching calls you meant to allow.

![Tool History filtered to blocked calls](screenshots/tool-history-blocked.png)

![The rule list with a deny rule expanded](screenshots/rule-list.png)

## When changes take effect

A change applies to the next tool call in a new turn. A chat turn or agent run that is already in progress keeps the rules it started with until its next turn.

## Next steps

- [Creating a rule](creating-a-rule.md)
- [Testing rules with the simulator](testing-rules-with-the-simulator.md)
- [Troubleshooting](troubleshooting.md)

---

## Navigation

### In this section: Tool Policies

- [Tool Policies](/docs/tool-policies/overview.md)
- [Use Cases and Playbooks](/docs/tool-policies/use-cases.md)
- [Creating a Rule](/docs/tool-policies/creating-a-rule.md)
- [Writing Conditions](/docs/tool-policies/writing-conditions.md)
- [Using a Tool as a Classifier](/docs/tool-policies/using-a-classifier.md)
- [Testing Rules with the Simulator](/docs/tool-policies/testing-rules-with-the-simulator.md)
- [Creating a Rule from a Tool Call](/docs/tool-policies/creating-a-rule-from-a-tool-call.md)
- **Managing the Rule List** (current)
- [Troubleshooting](/docs/tool-policies/troubleshooting.md)

#### Playbooks

- [Playbook: Build a Query Intent Classifier](/docs/tool-policies/playbook-query-intent-classifier.md)
- [Playbook: Control Where Your Tools Can Send Data](/docs/tool-policies/playbook-outbound-request-allowlist.md)
- [Playbook: Give a Scheduled Agent Only the Access It Needs](/docs/tool-policies/playbook-scheduled-agent-guardrails.md)
- [Playbook: Put Guardrails on Warehouse Queries](/docs/tool-policies/playbook-warehouse-query-guardrails.md)

### Other sections

- [Tool Creation](/docs/tool-creation/overview.md)
- [Subagents](/docs/subagents/overview.md)
- [Agent Skills](/docs/agent-skills/overview.md)
- [Sandcastles](/docs/sandcastles/overview.md)
- [MCP Servers](/docs/mcp-servers/overview.md)
- [Scheduled Triggers](/docs/scheduled-triggers/overview.md)
- [Agent Filesystem](/docs/agent-filesystem/overview.md)
- [Workspace Permissions](/docs/workspace-permissions/overview.md)
- [Workspace Billing](/docs/workspace-billing/overview.md)
- [Chat Sharing](/docs/chat-sharing/overview.md)

[Back to docs index](/docs.md)
