Skip to main content

Overview

The Policies page has three tabs: A policy suspension exempts one user or group from one policy. You can limit it to matching requests and to a time window. Suspensions are useful for break-glass access and for approved one-time operations.

Triggered Policies

Open Triggered Policies to see which requests policies acted on. A chart shows policy activity over the selected time range.
  • Columns: User, Resource, Technology, Event Type, Policies, Timestamp, and Actions
  • Filters: user, resource, action, policy status, policy, and technology
  • Row actions: Suspend opens the suspension dialog for that request. View log opens the log entry.
The tab reads from Logs, so it covers the same retention window.

Create a Suspension

1

Open the dialog

On Policy Suspensions, click Create Suspension. You can also click Suspend on a row in Triggered Policies.
2

Choose the policy and identity

Select the Policy. Set Identity Type to a user or a group, then select the Identity.
3

Choose the exception type

  • One-off: Applies to the first matching request, or until the safety timeout, whichever comes first.
  • Time-bound: Applies to every matching request until it expires.
4

Set the expiration

Set Expires After in minutes, hours, or days.
5

Narrow it down (optional)

Enter an Input Condition: a CEL expression on policy inputs that must be true for the suspension to apply. Leave it empty to cover every request.
6

Add a reason and save

Enter a Reason for the audit trail, then create the suspension.
Verify: The suspension appears in the Policy Suspensions tab with its type and Expires At time.

Write an Input Condition

The condition can read input, the same policy input the policy receives, and now, the current time. It must return a boolean. Examples:
If the condition doesn’t compile or doesn’t return a boolean, the suspension never applies. Formal doesn’t report an error.

Who a Suspension Covers

A user suspension applies when the request’s user or end user is that user. A group suspension applies when the user or end user is in that group.

Manage Suspensions

The Policy Suspensions tab lists Policy, Identity Type, Identity, Type, Reason, Input Condition, Expires At, ID, and Created. Type shows One-off or Persistent (time-bound). Delete a suspension to revoke it immediately. Formal also removes expired suspensions automatically.

Other Ways to Create Suspensions

  • Access Requests: Approving an employee’s exception request creates a suspension. See Access Requests.
  • Workflows: A workflow can call PolicySuspension with formal-app-command. See Workflows.
  • API: Call CreatePolicySuspension:
Always set oneoff. If you omit it, Formal treats a suspension with an input_condition as one-off and a suspension without one as time-bound. If you omit expiration_minutes, the suspension expires after 24 hours.

Next Steps

Access Requests

Let employees request exceptions

Operations

Test and troubleshoot policies