Skip to main content

Policy Rules

Policy rules are how you govern what AI Discovery finds. Each rule allows, warns on, or blocks discovered MCP servers and skills, scoped to the users, groups, or devices you choose. You manage them from the Policy Rules tab of the AI Discovery dashboard.

Rules are evaluated top-to-bottom, the first matching rule wins, and you can drag them to reorder.

Two default rules sit above the list, MCP Servers Default and Skills Default, which set the action when no rule matches. Filter the rules below by target (MCP Servers, Skills) and by state (Active, Draft). Each rule row shows its position, its target type, its action, and whether it is Active or Draft.

Before you define anything, the tab reads No policy rules defined and offers Add First Rule.

The Policy Rules tab with the two default rules, one draft Block rule, and the evaluation order panel

How rules are evaluated

Willow states the evaluation order on the page itself:

  1. Managed MCP servers (proxied through your gateway) are always allowed
  2. Rules scoped to a specific group, user, or device only apply to matching targets
  3. Rules are checked top-to-bottom, and the first match determines the action
  4. If nothing matches, the default action is applied
  5. Block rules targeting all users and devices org-wide require confirmation

Add a policy rule

Select Add Rule, or use the shield icon (Add to Policy Rule) on a discovered capability to pre-fill one.

The Add Policy Rule dialog set to All Unmanaged, warning that the rule would block all devices

FieldOptions
Rule NameFree text. The dialog prefixes it with the chosen action, for example Block:.
What to matchSpecific Capabilities or All Unmanaged.
CapabilitiesSearch and select discovered MCP servers or skills. Only when matching specific capabilities.
Applies ToMCP Servers, Skills, or All Capabilities.
ActionAllow, Warn, or Block.
ScopeEveryone (org-wide), Specific Groups, Specific Users, or Specific Devices.

Choosing All Unmanaged applies the rule to every unmanaged capability of the selected type. Managed capabilities, the ones proxied through your gateway, are always exempt.

An Estimated Impact panel updates as you configure the rule, showing how many capabilities match and how many devices and users are affected. If a rule would reach every device, Willow warns you to narrow the scope.

Publish a rule

Rules are saved with Save as Draft and do not enforce anything until published.

A draft rule's detail panel, showing its target, match type, priority, scope, capabilities, and the Publish Rule action

Select a rule to open its detail panel, which shows its action, target, match type, priority, creation date, scope, and the capabilities it covers, along with Publish Rule, Edit Rule, and Delete Rule.

Publishing asks for confirmation, warning that the rule "will become active and start enforcing immediately". The rule's badge then changes from Draft to Active.

On this page