Skip to main content
Actrail governs actions with policies, and you get them two ways — from the managed catalog Actrail installed when you connected, and from flags Actrail raises on your own trails. Both start in shadow, and you graduate them to enforce.

Enforce a managed policy

Open Runtime Policy

In the console, open Runtime Policy. You’ll see the managed rules Actrail installed — each in shadow.

Watch it in shadow

Use Claude Code as usual. A shadow policy records what it would block, so you see it match real actions before it binds anything.

Graduate to enforce

When the matches look right, switch the policy to enforce. From the next run, the matching action is blocked.

Turn a flag into a policy

Find your trail

Open Trails. Your session is a trail — the timeline of what the agent did.
Risks are detected when a session closes. A still-open session is normal.

Review a flag

Flagged risks land in the Inbox, each with a short explanation and the evidence.

Make a policy

Resolve the flag into a policy. It starts in shadow, then graduates like any other.

Shadow to enforce

Enforcing is the one moment a rule starts blocking your agent, so Actrail asks for evidence first: the policy should have actually been observed matching real actions in shadow, and the connected SDK must be able to produce the signals the rule depends on.
Testing before that evidence exists? An admin can “enforce now” to arm a policy immediately for a controlled trial. The choice and a reason are recorded.