Skip to content

Policy rules

Agent Guardrails → Rules (“Policy rules”, Pro) adds conditions to your permissions: refunds over 100 need a human, no more than 500 in refunds a day, no price change over 10%, nothing after 18:00. Rules run before the agent permission matrix, lowest priority first, and the first matching rule decides.

The Templates card creates ready-made rules. Choose Applies to (“All agents” or one agent) and click Add rule:

Template What it creates
Approve refunds over X (amount, default 100) Two Require approval rules (priority 5): any ability whose name contains “refund” with an amount above X, and any order status change to “refunded” where the order’s refundable amount is above X — including WooCommerce MCP’s orders-update.
Daily spending budget (budget per 24 hours, default 500) One Require approval rule (priority 4) on every financial ability. Once an agent’s refunds and other money-moving actions would add up to more than the budget within 24 hours, the next ones wait for a human. Actions a human approved count toward the budget too.
Cap price changes at Y% (percent, default 10) Require approval (priority 10) when a product update changes a price by more than Y% — woocommerce/product-update and WooCommerce MCP’s products-update.
Block deletes Deny every destructive ability (priority 1).
Business hours only (from 09:00, to 18:00) Deny write, financial and destructive abilities except between those hours Monday to Friday, in the site’s timezone — so weekends are blocked all day (priority 2).
Max N writes per hour (default 30) Deny once an agent exceeds N calls per hour to any one changing ability (priority 3).

Add rule opens the editor:

Field Options
Name Shown in the audit log (“Matched policy rule “…”.”).
Applies to All agents or one agent. A rule scoped to one agent is ignored for every other agent. The built-in agent is labelled “Site AI (in-site AI features only)”.
Match Exact ability; Pattern (e.g. woocommerce/*) — * matches anything including /, ? one character, case-insensitive; or Risk level(s) — comma-separated, e.g. financial,destructive.
Conditions (all must match) Add condition / Remove. With none, “the rule applies to every matching call.”
Then Require approval, Deny or Allow.
Priority (lower runs first) Default 10.
Enabled On by default.

If every rule on the page applies only to Site AI, a warning reminds you that external agents are not affected.

Condition Parameters Works with
Amount is greater than Amount Refund abilities (the amount, or the sum of line-item refunds), order status changes to refunded/cancelled (the order’s refundable amount), product create/update (the new price)
Change is greater than (%) Percent Product updates: the largest change among regular, sale and effective price (removing a sale counts)
Total amount in a period would exceed a budget Budget; Period (hours), 1–744, default 24 The same abilities as Amount is greater than. Matches when the agent’s spending in the period, plus this call’s amount, is above the budget. See Spending budgets.
Items in one call greater than Items Any ability: the longest list in the input
More calls than allowed per time window Max calls; Window (minutes), 1–1440, default 10 Any ability, counted per agent per ability
Time of day (site timezone) From (HH:MM), To (HH:MM), Days (1 = Monday … 7 = Sunday; empty = every day), Match when OUTSIDE this window Any ability; windows can cross midnight
Input field equals Field path (e.g. status), Value Any ability, case-insensitive
Input field is one of Field path, Values (comma-separated) Any ability

The editor only offers conditions the matched ability supports. With a Pattern or Risk level(s) match, Change is greater than (%) isn’t offered — use an exact ability (for example woocommerce/product-update) or the Cap price changes template.

A budget adds up money that an agent has already moved. Raqvio Agent Guardrails records the amount of every successful call to a financial ability: refunds (the refunded amount) and order status changes to refunded or cancelled (the order’s refundable amount). Calls a human approved are counted too. Calls that were denied, or are still waiting for approval, are not.

Each budget rule counts only the abilities it applies to, and only for the agent making the call. All unknown agents share one budget. So a rule on *refund* counts refunds only, and the Daily spending budget template (match: risk level financial) counts refunds and refunded or cancelled orders together.

The period is a rolling window that ends at the current call, for example the last 24 hours. Two calls that arrive at exactly the same moment can both pass the check.

A Deny or Require approval rule that depends on an amount or percentage fails closed: if Raqvio Agent Guardrails can’t determine the value (for example the product doesn’t exist), the rule still matches. An Allow rule doesn’t match in that case. Rules judge the input after the ability’s defaults are applied.

At the bottom of the rule editor, Test on past activity replays recent agent calls from the audit log with your draft rule added to your enabled rules. Choose the Period (last 24 hours, 7 days or 30 days) and click Run test. Nothing is saved and nothing runs.

The result says how many calls were checked, how many the rule would decide, and how many would get a different outcome than they did. A table lists the calls with their Recorded decision and the decision With this rule, changed ones first. It also tells you when:

  • more calls match the rule, but a rule with a lower priority number decides them first;
  • some matched calls have no stored input (sensitive or very large), so conditions on their amounts or fields were counted as matching;
  • only the most recent 2,000 calls were checked.

The replay has limits, and the result lists the ones that apply to your rule:

  • Price changes and order amounts are measured against your products and orders as they are now, not as they were at the time of each call.
  • Rate limits and budgets only count calls inside the replayed period.
  • The audit log stores input with personal data masked, so conditions on masked fields may not match.
  • Periods when the kill switch was on, or an agent was paused, are not taken into account.
  • Deny: raqvio_ag_denied (403) — “Blocked by Raqvio Agent Guardrails: Matched policy rule “…”.”
  • Require approval: raqvio_ag_approval_required (202) with the approval id — see Approvals.
  • raqvio-ag/get-my-permissions reports a rule that decides as “A policy rule applies.” without naming it. Rules with conditions aren’t evaluated there; their possible decisions are listed in conditional. The check never counts toward rate limits.

Saving and deleting rules is recorded in the audit log.