Skip to content

Start from observed traffic

Observed traffic helps teams discover the action names and attributes their agents actually send.

  1. Open Agents and select the new agent.
  2. Review its recently observed actions.
  3. Choose an action and start a policy from that traffic.
  4. Keep only the attributes required for the intended control.
  5. Add tests, publish the reviewed version, and assign it to the agent.

Observation is not authorization. A recorded activity reports that an action was seen; it does not prove that Actera authorized it or that a managed external operation completed.

During gradual onboarding, the agent fallback can allow actions without an applicable policy. An applicable policy whose rules do not match blocks by default.