Skip to content

Learn · Services

Rules

Say what to do when something is wrong.

Checked against the product on · written for everyone

A rule pairs a when with a then. The when is a warning label from your installed rule packs. The then comes from one fixed list of actions, the same in every authoring surface.

console.dmzagent.com/rules

Respond

Rules

1All labelsOnNew rule
2
RuleWhen this is seenDo thisSign-offState
Overheat holdtemperature-excursionHoldNot neededOn
Escalate repeatrepeat-excursionEscalateNot neededOn
Cut accesscredential-exposureTurn off accessRequiredOn
Log onlylow-confidenceWrite it downNot neededOn
Figure. Four rules, each naming a label, an action, and whether sign-off is required. The rules list with four rules, the warning label each watches, the action each takes, and whether it is on.

The fixed action list

Every action a rule can take.
GroupActionsReaches your systems
Write it downRecordNo. Always on.
Tell a personNotify · Ask for review · EscalateNo.
Gate the actionAllow · Challenge · Hold · BlockThe thing in flight only.
Fix itTurn off access · Switch off · Open a ticket · Call your systemYes, through a bound connector.
Safe by default. A rule pack adds warning labels. The action list stays the same for every account, so installing a pack can never grant an action your account did not already have.

Build-up rules

A build-up rule handles a weak signal that keeps coming back. Each repeat steps the response up, and older events fade on a half-life. One odd reading stays quiet; a pattern gets attention.

The three standings a build-up rule produces.
StandingMeansA guard check answers
AllowedNothing has built up.allow
Take a lookSignals are accumulating.take a look
HeldThe threshold was crossed.block

When two rules fire

The most careful action wins. A rule that blocks beats one that notifies, and a sensitive action is held for a person whatever else fired.