Overview
A policy stage configuration turns off policy evaluation at one or more stages for a single Resource or Connector. Use it to roll out policies one stage at a time, or to exempt a Resource without editing every policy. Each configuration has three switches:
A skipped stage enforces nothing and records no triggered policies. Policies stay active everywhere else.
Scope and Precedence
A configuration targets exactly one Resource or one Connector. Each Resource and each Connector can have at most one configuration. When a Connector handles traffic for a Resource, it looks for a configuration in this order:- The configuration for the Resource
- The configuration for the Connector
- No configuration: every stage is evaluated
Manage Configurations
Stage configurations are managed through the API. The Control Plane and the Terraform provider don’t expose them yet.1
Create a configuration
Set The response contains the configuration and its
resource_id or connector_id, plus the stages to turn off:id.2
List configurations
3
Update a configuration
Send only the switches you want to change:
UpdatePolicyStageConfigurationV2 replaces the whole object instead.4
Delete a configuration
Example: Roll Out S3 Masking
To activate a new S3 policy one stage at a time:- Create a configuration for the S3 Resource with
disable_response_policy_evaluationset totrue. - Activate the policy and confirm that its
sessionandrequestrules behave as expected in Logs. - Update the configuration to set
disable_response_policy_evaluationtofalse. - Download a CSV object and confirm the masked columns.
Troubleshooting
A stage still evaluates after you turned it off
A stage still evaluates after you turned it off
Cause: The Resource is not an S3 Resource, or a Resource configuration overrides the Connector one. Fix: Check the technology, then list configurations and look for one with the Resource’s ID.
Creating a configuration fails
Creating a configuration fails
Cause: The Resource or Connector already has a configuration. Fix: Update the existing configuration instead.
Next Steps
Operations
Test, roll out, and troubleshoot policies
S3
Protect S3 buckets with Formal