Developer documentation

Exceptions

Exceptions apply an explicit trusted or blocked match before ordinary policy rules.

Add narrowly

Choose the identifier type, optional benefit, reason, and optional expiry. Blocked matches take precedence over trusted matches.

Delete intentionally

Deleting an exception takes effect for new evaluations immediately and cannot be reversed. REST and MCP requests require exceptions:write and a stable idempotency key.