Policy rules
Agent Guardrails → Rules (“Policy rules”, Pro) adds conditions to your permissions: refunds over 100 need a human, no more than 500 in refunds a day, no price change over 10%, nothing after 18:00. Rules run before the agent permission matrix, lowest priority first, and the first matching rule decides.
Start with a template
Section titled “Start with a template”The Templates card creates ready-made rules. Choose Applies to (“All agents” or one agent) and click Add rule:
| Template | What it creates |
|---|---|
| Approve refunds over X (amount, default 100) | Two Require approval rules (priority 5): any ability whose name contains “refund” with an amount above X, and any order status change to “refunded” where the order’s refundable amount is above X — including WooCommerce MCP’s orders-update. |
| Daily spending budget (budget per 24 hours, default 500) | One Require approval rule (priority 4) on every financial ability. Once an agent’s refunds and other money-moving actions would add up to more than the budget within 24 hours, the next ones wait for a human. Actions a human approved count toward the budget too. |
| Cap price changes at Y% (percent, default 10) | Require approval (priority 10) when a product update changes a price by more than Y% — woocommerce/product-update and WooCommerce MCP’s products-update. |
| Block deletes | Deny every destructive ability (priority 1). |
| Business hours only (from 09:00, to 18:00) | Deny write, financial and destructive abilities except between those hours Monday to Friday, in the site’s timezone — so weekends are blocked all day (priority 2). |
| Max N writes per hour (default 30) | Deny once an agent exceeds N calls per hour to any one changing ability (priority 3). |
Create or edit a rule
Section titled “Create or edit a rule”Add rule opens the editor:
| Field | Options |
|---|---|
| Name | Shown in the audit log (“Matched policy rule “…”.”). |
| Applies to | All agents or one agent. A rule scoped to one agent is ignored for every other agent. The built-in agent is labelled “Site AI (in-site AI features only)”. |
| Match | Exact ability; Pattern (e.g. woocommerce/*) — * matches anything including /, ? one character, case-insensitive; or Risk level(s) — comma-separated, e.g. financial,destructive. |
| Conditions (all must match) | Add condition / Remove. With none, “the rule applies to every matching call.” |
| Then | Require approval, Deny or Allow. |
| Priority (lower runs first) | Default 10. |
| Enabled | On by default. |
If every rule on the page applies only to Site AI, a warning reminds you that external agents are not affected.
Condition types
Section titled “Condition types”| Condition | Parameters | Works with |
|---|---|---|
| Amount is greater than | Amount | Refund abilities (the amount, or the sum of line-item refunds), order status changes to refunded/cancelled (the order’s refundable amount), product create/update (the new price) |
| Change is greater than (%) | Percent | Product updates: the largest change among regular, sale and effective price (removing a sale counts) |
| Total amount in a period would exceed a budget | Budget; Period (hours), 1–744, default 24 | The same abilities as Amount is greater than. Matches when the agent’s spending in the period, plus this call’s amount, is above the budget. See Spending budgets. |
| Items in one call greater than | Items | Any ability: the longest list in the input |
| More calls than allowed per time window | Max calls; Window (minutes), 1–1440, default 10 | Any ability, counted per agent per ability |
| Time of day (site timezone) | From (HH:MM), To (HH:MM), Days (1 = Monday … 7 = Sunday; empty = every day), Match when OUTSIDE this window | Any ability; windows can cross midnight |
| Input field equals | Field path (e.g. status), Value |
Any ability, case-insensitive |
| Input field is one of | Field path, Values (comma-separated) | Any ability |
The editor only offers conditions the matched ability supports. With a Pattern or Risk level(s) match, Change is greater than (%) isn’t offered — use an exact ability (for example woocommerce/product-update) or the Cap price changes template.
Spending budgets
Section titled “Spending budgets”A budget adds up money that an agent has already moved. Raqvio Agent Guardrails records the amount of every successful call to a financial ability: refunds (the refunded amount) and order status changes to refunded or cancelled (the order’s refundable amount). Calls a human approved are counted too. Calls that were denied, or are still waiting for approval, are not.
Each budget rule counts only the abilities it applies to, and only for the agent making the call. All unknown agents share one budget. So a rule on *refund* counts refunds only, and the Daily spending budget template (match: risk level financial) counts refunds and refunded or cancelled orders together.
The period is a rolling window that ends at the current call, for example the last 24 hours. Two calls that arrive at exactly the same moment can both pass the check.
When a value can’t be determined
Section titled “When a value can’t be determined”A Deny or Require approval rule that depends on an amount or percentage fails closed: if Raqvio Agent Guardrails can’t determine the value (for example the product doesn’t exist), the rule still matches. An Allow rule doesn’t match in that case. Rules judge the input after the ability’s defaults are applied.
Test a rule on past activity
Section titled “Test a rule on past activity”At the bottom of the rule editor, Test on past activity replays recent agent calls from the audit log with your draft rule added to your enabled rules. Choose the Period (last 24 hours, 7 days or 30 days) and click Run test. Nothing is saved and nothing runs.
The result says how many calls were checked, how many the rule would decide, and how many would get a different outcome than they did. A table lists the calls with their Recorded decision and the decision With this rule, changed ones first. It also tells you when:
- more calls match the rule, but a rule with a lower priority number decides them first;
- some matched calls have no stored input (sensitive or very large), so conditions on their amounts or fields were counted as matching;
- only the most recent 2,000 calls were checked.
The replay has limits, and the result lists the ones that apply to your rule:
- Price changes and order amounts are measured against your products and orders as they are now, not as they were at the time of each call.
- Rate limits and budgets only count calls inside the replayed period.
- The audit log stores input with personal data masked, so conditions on masked fields may not match.
- Periods when the kill switch was on, or an agent was paused, are not taken into account.
What agents see
Section titled “What agents see”- Deny:
raqvio_ag_denied(403) — “Blocked by Raqvio Agent Guardrails: Matched policy rule “…”.” - Require approval:
raqvio_ag_approval_required(202) with the approval id — see Approvals. raqvio-ag/get-my-permissionsreports a rule that decides as “A policy rule applies.” without naming it. Rules with conditions aren’t evaluated there; their possible decisions are listed inconditional. The check never counts toward rate limits.
Saving and deleting rules is recorded in the audit log.