Software Secure Workload
Activity Configure

Approved Policies

In general, approved policies are not changed during automatic policy discovery, and automatic policy discovery does not suggest policies that would duplicate or overlap the effects of approved policies.

The following are approved policies:

  • Manually created policies.

  • Discovered policies that are manually approved.

    (When you are satisfied that a policy behaves as intended, you approve it to protect it from changes during future automatic policy discovery. See Approve Policies.)

  • Uploaded policies, unless explicitly marked as approved: false.

  • Approved policies that are defined in parent and ancestor scopes (specifically, from the latest versions of their primary workspaces) that apply to workloads in this scope.

  • Policies created when policy requests are accepted from another workspace when cross-scope policies are handled using the advanced method that is described in When Consumer and Provider Are in Different Scopes: Policy Options. For example, this includes policies that are included from the Provided Services tab.

Approved policies are shown with a thumbs-up icon next to the protocol type when you click a policy's ports or protocols link and view details in the panel at the right side of the page.

Exceptions to Approved Policy Protections

Approved policies are preserved during future automatic policy discovery if both ends of the policy are any of: approved cluster; inventory filter; accepted policy request (for cross-scope policies); or a cluster that doesn’t significantly change membership. (However, the cluster membership may have changed in the last case.)

Approved policies may not be protected during future automatic policy discovery runs if either end of the policy is a cluster that is not approved, and if, upon automatic policy discovery, no newly generated cluster has sufficiently high overlap with such cluster.

To protect a policy that involves an unapproved cluster, you should explicitly approve the clusters at each end of the policy.

There is also an advanced configuration for automatic policy discovery that is enabled by default. If you do not want to protect approved policies from changes, you can deselect this option for a workspace or for the global default policy discovery configuration:. See Carry over Approved Policies.