Policy Structure
An AARM policy has three parts:Match Conditions
Tool and Operation
Match specific tools and operations:Parameters
Match parameter values:Context
Match session context:Risk Signals
Match computed risk scores:Actions
| Action | Behavior |
|---|---|
ALLOW | Execute the action |
DENY | Block with reason |
MODIFY | Rewrite parameters, then execute |
STEP_UP | Require human approval |
MODIFY Example
Cap query results:STEP_UP Example
Require approval for destructive operations:Common Patterns
Block External Data Transfer
Destination Allowlist
Rate Limiting
Require Approval Above Threshold
Testing Policies
Test policies before deployment:Next Steps
Approval Flows
Implement step-up authorization
Receipt Signing
Cryptographic audit trails