Reference

Troubleshooting

Common issues and solutions related to tool policies.

Common issues and solutions related to tool policies.


My rule never blocks anything

The rule is not matching the calls you expect. Check these in order:

  • Look at the line under the target in the rule editor. If it says no tool in the workspace matches, the tool name or tool pack is misspelled.
  • Check the Path on each condition. A warning under the field means the tool has no parameter by that name.
  • Check whether the rule is limited to certain Sources. A rule limited to Chat does not apply to agents.
  • Check the order. A rule higher in the list may be allowing the call first.

Run the call through the simulator. The trace shows which rule decided and why each of the others was skipped.


A value with an asterisk does not match

Text operators match exactly what you type. In contains, equals, starts_with, and ends_with, an asterisk is looked for as an asterisk. Wildcards only work in the Tool pack and Tool fields.

To match a pattern in a value, change the operator to matches. For "starts with foo bar baz, followed by anything", use foo bar baz.*.


The rule misses values written in a different case

Matching is case sensitive unless you say otherwise. Tick ignore case on the condition.


My pattern does not match text that spans several lines

In a pattern, a dot does not match a line break. Replace .* with [\s\S]* when the value can contain line breaks, as queries and code often do.


The editor rejects my pattern

The pattern is invalid or could be slow to evaluate. The message under the field says which. Patterns with nested repetition such as (a+)+, patterns that refer back to an earlier group, and very long patterns are not accepted. Rewrite the pattern without them.


A call gets through when a parameter is left out

not_equals, not_in, and url_host_not_in only match when the parameter is present. If the tool allows the parameter to be omitted, add a second rule on the same tool using the missing operator.


A subdomain is not matched by my host list

Host entries match the whole host. acme.com does not cover api.acme.com. Start the entry with a dot, .acme.com, to cover the domain and its subdomains.


The simulator says a call is allowed, but the real call was blocked

The two were not evaluated the same way. Check that:

  • The User in the simulator is the person who made the call.
  • The Source matches where the call came from.
  • If an agent made the call, that agent is selected in Agent (optional). Rules that apply to an agent are skipped otherwise.
  • The values in Params JSON are the ones from the real call. Copy them from Execution Details in Tool History.
  • The rules have not changed since the call was made.

The simulator says the user is not a member of this workspace

The simulator only evaluates people who belong to the workspace. Pick a current member. People who have been removed cannot be simulated.


Everything stopped working after I changed the default

The default is set to Deny and no allow rule covers the tool. With a default of Deny, every tool needs an allow rule. Set the Default row back to Allow to restore access, then add allow rules before switching again. See Setting the workspace default.


A classifier rule blocks every call

The classifier is failing and the rule is set to fail closed. Run the call through the simulator and read the classifier line in the trace. Common causes:

  • The classifier tool name is misspelled or the tool was removed.
  • The Input does not provide a parameter the classifier requires.
  • The classifier takes longer than the Timeout.

The test in the rule editor ignores my classifier

The editor's test checks ordinary conditions only. Save the rule and use the simulator, which runs classifiers.


I cannot move a rule

The rule is already at that end of the list, or another change is still saving. Move up is unavailable on the first rule and Move down on the last. If both are available and nothing happens, wait a moment and try again.


Saving fails with "That priority is already used by another rule"

Two rules cannot share a position. Use Move up, Move down, or Placement to change the order.


I changed a rule but a running agent is still blocked

A run in progress keeps the rules it started with. The change applies on the agent's next turn or next run.


I do not see New Rule or the option to create a rule from a call

You are not a workspace admin. Members can view tool policies but cannot change them. Ask a workspace admin to make the change or to update your role.


The AI keeps retrying a blocked call

The message the AI receives does not tell it what to do instead. Edit the rule and write a clearer Message returned to the model on deny, such as "This table is restricted. Use the monthly_summary view instead."


Still need help? Contact your workspace administrator.