Policy Rules
Policy rules are how you govern what AI Discovery finds. Each rule allows, warns on, or blocks discovered MCP servers and skills, scoped to the users, groups, or devices you choose. You manage them from the Policy Rules tab of the AI Discovery dashboard.
Rules are evaluated top-to-bottom, the first matching rule wins, and you can drag them to reorder.
Two default rules sit above the list, MCP Servers Default and Skills Default, which set the action when no rule matches. Filter the rules below by target (MCP Servers, Skills) and by state (Active, Draft). Each rule row shows its position, its target type, its action, and whether it is Active or Draft.
Before you define anything, the tab reads No policy rules defined and offers Add First Rule.

How rules are evaluated
Willow states the evaluation order on the page itself:
- Managed MCP servers (proxied through your gateway) are always allowed
- Rules scoped to a specific group, user, or device only apply to matching targets
- Rules are checked top-to-bottom, and the first match determines the action
- If nothing matches, the default action is applied
- Block rules targeting all users and devices org-wide require confirmation
Add a policy rule
Select Add Rule, or use the shield icon (Add to Policy Rule) on a discovered capability to pre-fill one.

| Field | Options |
|---|---|
| Rule Name | Free text. The dialog prefixes it with the chosen action, for example Block:. |
| What to match | Specific Capabilities or All Unmanaged. |
| Capabilities | Search and select discovered MCP servers or skills. Only when matching specific capabilities. |
| Applies To | MCP Servers, Skills, or All Capabilities. |
| Action | Allow, Warn, or Block. |
| Scope | Everyone (org-wide), Specific Groups, Specific Users, or Specific Devices. |
Choosing All Unmanaged applies the rule to every unmanaged capability of the selected type. Managed capabilities, the ones proxied through your gateway, are always exempt.
An Estimated Impact panel updates as you configure the rule, showing how many capabilities match and how many devices and users are affected. If a rule would reach every device, Willow warns you to narrow the scope.
Publish a rule
Rules are saved with Save as Draft and do not enforce anything until published.

Select a rule to open its detail panel, which shows its action, target, match type, priority, creation date, scope, and the capabilities it covers, along with Publish Rule, Edit Rule, and Delete Rule.
Publishing asks for confirmation, warning that the rule "will become active and start enforcing immediately". The rule's badge then changes from Draft to Active.