> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Triggered Policies and Policy Suspensions

> Review the requests that triggered policies and grant time-bound or one-off exceptions

## Overview

The [Policies](https://app.formal.ai/policies) page has three tabs:

| Tab | Shows |
| - | - |
| **Policies** | Your policies |
| **Triggered Policies** | Requests that triggered at least one policy |
| **Policy Suspensions** | Active exceptions to policies |

A **policy suspension** exempts one user or group from one policy. You can limit it to matching requests and to a time window. Suspensions are useful for break-glass access and for approved one-time operations.

## Triggered Policies

Open [Triggered Policies](https://app.formal.ai/policies?tab=triggered-policies) to see which requests policies acted on. A chart shows policy activity over the selected time range.

* **Columns:** **User**, **Resource**, **Technology**, **Event Type**, **Policies**, **Timestamp**, and **Actions**
* **Filters:** user, resource, action, policy status, policy, and technology
* **Row actions:** **Suspend** opens the suspension dialog for that request. **View log** opens the log entry.

The tab reads from [Logs](/docs/guides/observability/logs), so it covers the same retention window.

## Create a Suspension

<Steps>
  <Step title="Open the dialog">
    On [Policy Suspensions](https://app.formal.ai/policies?tab=suspensions), click **Create Suspension**. You can also click **Suspend** on a row in **Triggered Policies**.
  </Step>

  <Step title="Choose the policy and identity">
    Select the **Policy**. Set **Identity Type** to a user or a group, then select the **Identity**.
  </Step>

  <Step title="Choose the exception type">
    * **One-off:** Applies to the first matching request, or until the safety timeout, whichever comes first.
    * **Time-bound:** Applies to every matching request until it expires.
  </Step>

  <Step title="Set the expiration">
    Set **Expires After** in minutes, hours, or days.
  </Step>

  <Step title="Narrow it down (optional)">
    Enter an **Input Condition**: a [CEL](https://cel.dev/) expression on policy inputs that must be true for the suspension to apply. Leave it empty to cover every request.
  </Step>

  <Step title="Add a reason and save">
    Enter a **Reason** for the audit trail, then create the suspension.
  </Step>
</Steps>

**Verify:** The suspension appears in the **Policy Suspensions** tab with its type and **Expires At** time.

### Write an Input Condition

The condition can read `input`, the same [policy input](/docs/guides/policies/evaluation) the policy receives, and `now`, the current time. It must return a boolean. Examples:

```cel theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
input.resource.name == "prod-postgres"
```

```cel theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
input.sql_query.statement_type == "DELETE" && input.db_name == "billing"
```

<Warning>
  If the condition doesn't compile or doesn't return a boolean, the suspension
  never applies. Formal doesn't report an error.
</Warning>

### Who a Suspension Covers

A user suspension applies when the request's user or end user is that user. A group suspension applies when the user or end user is in that group.

## Manage Suspensions

The **Policy Suspensions** tab lists **Policy**, **Identity Type**, **Identity**, **Type**, **Reason**, **Input Condition**, **Expires At**, **ID**, and **Created**. **Type** shows **One-off** or **Persistent** (time-bound).

Delete a suspension to revoke it immediately. Formal also removes expired suspensions automatically.

## Other Ways to Create Suspensions

* **Access Requests:** Approving an employee's exception request creates a suspension. See [Access Requests](/docs/guides/ai-governance/access-requests).
* **Workflows:** A workflow can call `PolicySuspension` with `formal-app-command`. See [Workflows](/docs/guides/configuration/workflows).
* **API:** Call `CreatePolicySuspension`:

```bash theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
curl -X POST "https://api.joinformal.com/core.v1.PoliciesService/CreatePolicySuspension" \
  -H "X-API-KEY: <YOUR_API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
    "policy_id": "<POLICY_ID>",
    "identity_type": "user",
    "identity_id": "<USER_ID>",
    "oneoff": false,
    "expiration_minutes": 60,
    "input_condition": "input.resource.name == \"prod-postgres\"",
    "reason": "Incident 4521 remediation"
  }'
```

<Note>
  Always set `oneoff`. If you omit it, Formal treats a suspension with an
  `input_condition` as one-off and a suspension without one as time-bound. If
  you omit `expiration_minutes`, the suspension expires after 24 hours.
</Note>

## Next Steps

<CardGroup cols={2}>
  <Card title="Access Requests" icon="user-check" href="/docs/guides/ai-governance/access-requests">
    Let employees request exceptions
  </Card>

  <Card title="Operations" icon="wrench" href="/docs/guides/policies/operations">
    Test and troubleshoot policies
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.