Overview
The Policies page has three tabs:
A policy suspension exempts one user or group from one policy. You can limit it to matching requests and to a time window. Suspensions are useful for break-glass access and for approved one-time operations.
Triggered Policies
Open Triggered Policies to see which requests policies acted on. A chart shows policy activity over the selected time range.- Columns: User, Resource, Technology, Event Type, Policies, Timestamp, and Actions
- Filters: user, resource, action, policy status, policy, and technology
- Row actions: Suspend opens the suspension dialog for that request. View log opens the log entry.
Create a Suspension
1
Open the dialog
On Policy Suspensions, click Create Suspension. You can also click Suspend on a row in Triggered Policies.
2
Choose the policy and identity
Select the Policy. Set Identity Type to a user or a group, then select the Identity.
3
Choose the exception type
- One-off: Applies to the first matching request, or until the safety timeout, whichever comes first.
- Time-bound: Applies to every matching request until it expires.
4
Set the expiration
Set Expires After in minutes, hours, or days.
5
Narrow it down (optional)
Enter an Input Condition: a CEL expression on policy inputs that must be true for the suspension to apply. Leave it empty to cover every request.
6
Add a reason and save
Enter a Reason for the audit trail, then create the suspension.
Write an Input Condition
The condition can readinput, the same policy input the policy receives, and now, the current time. It must return a boolean. Examples:
Who a Suspension Covers
A user suspension applies when the request’s user or end user is that user. A group suspension applies when the user or end user is in that group.Manage Suspensions
The Policy Suspensions tab lists Policy, Identity Type, Identity, Type, Reason, Input Condition, Expires At, ID, and Created. Type shows One-off or Persistent (time-bound). Delete a suspension to revoke it immediately. Formal also removes expired suspensions automatically.Other Ways to Create Suspensions
- Access Requests: Approving an employee’s exception request creates a suspension. See Access Requests.
- Workflows: A workflow can call
PolicySuspensionwithformal-app-command. See Workflows. - API: Call
CreatePolicySuspension:
Always set
oneoff. If you omit it, Formal treats a suspension with an
input_condition as one-off and a suspension without one as time-bound. If
you omit expiration_minutes, the suspension expires after 24 hours.Next Steps
Access Requests
Let employees request exceptions
Operations
Test and troubleshoot policies