DB-authored rules only take effect for a caller once the
tool_gateway_db_rules feature flag is enabled for them β
create/enable it from Feature Flags
to stage the rollout (allowed groups / rollout %). With the flag off
or absent, rules below are stored but not yet applied β behavior stays
on the code-resident default ruleset.
π Policy Rules
Strongest-decision-wins across every matching rule (deny > require_approval > allow); priority is only a tiebreak within that decision. A rule can only narrow the default, never widen it.
Name
Priority
Tool
Action
Surface
Subject
Decision
Status
Loadingβ¦
β Add Rule
π§ͺ Dry-Run Simulator
Runs the exact same ToolPolicyEngine.evaluate() that tool_dispatcher and the MCP gate use, against the live rule set β nothing executes.
π§Ύ Decision Log
Real tool_dispatcher / MCP-gate decisions, read from the existing audit trail (no new table) β the same explainability fields the simulator shows above, but for what actually happened.