DocumentationApprovals

Smart Holds

Flag false positives and review proposed policy refinements without automatic changes.

Updated 2026-09-22 Read as Markdown
On this page

Review hold history

Use the console’s Approvals → History view to inspect how pending and resolved checkpoints behaved. Distinguish human decisions, expirations, cancellations, and unenforced outcomes before deciding a rule needs refinement.

Flag a false positive

Inspect the action and matched rule, then record the appropriate verdict. A newer verdict can supersede an earlier false-positive flag. A denied or expired action is not automatically a false positive; confirm what the action actually attempted.

Request a narrower rule

For an eligible flagged decision, request a suggested fix. The current implementation runs narrowing as an async AI job. Review the original rule, proposed replacement, available replay evidence, and effect changes before installing.

A replacement from HOLD to MONITOR changes enforcement. It must not be described as merely narrowing a pattern. Suggested changes do not become policy without administrator review.

Daily suggestions

The configured hold-review service can propose recommendations from recent behavior. These remain suggestions. Applying a false-positive replacement has a separation-of-duties check against the recorded reviewers; this is distinct from a universal guarantee across every approval integration.

Verify the correction

Retest the harmless case and the risky action the original policy was intended to stop. Confirm that exemptions remain intact. After installation, monitor outcomes in the intended environment and retain a rollback path.