Skip to main content

Overview

A policy stage configuration turns off policy evaluation at one or more stages for a single Resource or Connector. Use it to roll out policies one stage at a time, or to exempt a Resource without editing every policy. Each configuration has three switches: A skipped stage enforces nothing and records no triggered policies. Policies stay active everywhere else.
Connectors currently apply stage configurations to S3 Resources only. Every other technology evaluates all stages, whatever the configuration says.

Scope and Precedence

A configuration targets exactly one Resource or one Connector. Each Resource and each Connector can have at most one configuration. When a Connector handles traffic for a Resource, it looks for a configuration in this order:
  1. The configuration for the Resource
  2. The configuration for the Connector
  3. No configuration: every stage is evaluated
Formal uses the first configuration it finds, as a whole. It does not merge switches from the Resource and Connector configurations.

Manage Configurations

Stage configurations are managed through the API. The Control Plane and the Terraform provider don’t expose them yet.
1

Create a configuration

Set resource_id or connector_id, plus the stages to turn off:
The response contains the configuration and its id.
2

List configurations

Verify: the new configuration appears with the expected switches.
3

Update a configuration

Send only the switches you want to change:
UpdatePolicyStageConfigurationV2 replaces the whole object instead.
4

Delete a configuration

After deletion, every stage is evaluated again, unless a Connector configuration still applies.
Connectors receive changes without a restart. See the API reference for the full request and response schemas.

Example: Roll Out S3 Masking

To activate a new S3 policy one stage at a time:
  1. Create a configuration for the S3 Resource with disable_response_policy_evaluation set to true.
  2. Activate the policy and confirm that its session and request rules behave as expected in Logs.
  3. Update the configuration to set disable_response_policy_evaluation to false.
  4. Download a CSV object and confirm the masked columns.

Troubleshooting

Cause: The Resource is not an S3 Resource, or a Resource configuration overrides the Connector one. Fix: Check the technology, then list configurations and look for one with the Resource’s ID.
Cause: The Resource or Connector already has a configuration. Fix: Update the existing configuration instead.

Next Steps

Operations

Test, roll out, and troubleshoot policies

S3

Protect S3 buckets with Formal