Modes
Basic manual/CLI creation starts Disabled. Discovery may explicitly create in Observe. Web Activity proposals use Observe, and source-update replacements return to Observe. Check the mode shown before saving or applying a review.
Allow and Block
Before-action rules can express ALLOW or BLOCK. Actions normally useblock-only: no blocking match means the action can proceed. Creating an Allow rule moves its covered actions to allow-block, which records explicit Allow, Block or Undetermined outcomes. Only an enforced Block prevents execution; Undetermined is not an enforced deny.
An Allow match does not override an enforced Block from another applicable Rule. When only Observe releases block, the effective disposition is Would block; if an Enforce release blocks, it is Block. Test the combined active set as well as the Rule you are reviewing.
Allow rules apply before actions, not as an Allow authoring option for response or result rules. An action with an active Allow rule cannot return to block-only until that covering Rule is disabled or archived.
Decisions need an enforcement boundary
The policy API returns a decision. Your SDK callback or direct integration must honor it before the effect. A guard on one path cannot protect another path that bypasses it.
An Executed receipt means the handler was invoked, not necessarily that it succeeded. No receipt means the applied outcome is unconfirmed. Traces combine policy evidence with actual runtime reports.