Skip to content
User Guide

Govern

Govern is where you set the rules MisterShell enforces at runtime across your estate. It is a top-level area in the main navigation (the page itself is titled Policies), and it groups every policy engine on one page as a set of tabs. Each governs a different stream of activity, and most are ordered lists of rules evaluated top to bottom, first match wins:

PolicyGovernsOn a match it can…Edition / add-on
Session PolicyInteractive sessions — both when a session opens and each command typed in a shellAccept or Deny (and optionally notify / log)Enterprise
Recording PolicyInteractive sessions, at connection timeRecord or Skip, choosing the store and retentionEnterprise
File Transfer PolicyCopies between the file catalog and compatible resourcesAccept or Deny (and optionally notify / log)Enterprise
Fact PolicyThe collected facts about each resourceMark a resource pass / fail against a compliance ruleEnterprise
Config PolicyDevice configurationBind a configuration stack to matching resources, to render and pushEnterprise
IDS PolicyEach intrusion-detection alert your sensors raiseAny combination of Notify and Log, or SuppressIDS Sensors add-on
Syslog PolicyEach device log record your collectors ingestAny combination of Log, Notify, and Forward, or DiscardSyslog Collector add-on

The edition / add-on column describes what your license must include to make changes and have the policy take effect — it never hides anything. Which tabs you see is decided purely by your role’s permissions (below). Without the required entitlement, the create/edit buttons on a tab show a lock, and the Enterprise-gated policies also stop acting: session rules are not enforced (neither at connection nor per command), sessions are not recorded, and fact rules are not evaluated. Definitions and previously collected evidence always remain visible.

Config Policy works a little differently from the rest: rather than reacting to a stream of activity, you author configuration templates and stacks and bind them to resources, then render and push them from each resource’s Configure tab.

Two of the policies reference a reusable building block, kept in its own sub-view of the same tab (a Rules / ACLs or Rules / Checks toggle in the tab’s toolbar) so it can be maintained once and referenced by many rules:

  • Session ACLs — named sets of command patterns that Session Policy rules match against (for example a shared “read-only SQL” or “dangerous shell commands” set).
  • Fact Checks — named sets of assertions that Fact Policy rules evaluate (for example “NTP synchronized,” “no Telnet listener”).

How the policies fit together

Each policy is an independent, ordered decision chain over its own input stream. They share the same evaluation model but never interfere with one another:

flowchart LR
  sess["Interactive session<br/>connection · each command"]
  facts["Collected facts"]
  logs["Ingested device logs"]
  alerts["IDS alerts"]

  subgraph govern["Govern · runtime policy engines"]
    direction TB
    sp["Session Policy<br/>accept / deny"]
    rp["Recording Policy<br/>record / skip"]
    fp["Fact Policy<br/>pass / fail"]
    syp["Syslog Policy<br/>log / notify / forward / discard"]
    ip["IDS Policy<br/>suppress / notify / log"]
  end

  sess --> sp
  sess --> rp
  facts --> fp
  logs --> syp
  alerts --> ip

  sp -. "notify / log" .-> out["Automation events ·<br/>Policy Log · your SIEM"]
  fp -. "compliance change" .-> out
  syp -. "notify / forward" .-> out
  ip -. "notify / log" .-> out

A Notify action on any policy raises an automation event, so you can wire alerts, emails, or webhooks to policy decisions. Session Policy decisions with Log on are also written to the Policy Log audit trail, and Fact Policy results feed the Compliance heatmap.

Permissions

Policy selectors show location paths, tag names, role names and sensor names across the estate where those selectors apply. Reading the relevant policy is sufficient to see these choices; it does not grant access to the resources, role membership, sensor operation or credentials behind them. Policy hit counters also remain global.

Each tab is shown or hidden independently by your role’s read permission — you see only the policies your role allows (the license, by contrast, only locks changes; it never hides a tab):

  • Session Policy, Session ACLs, and Recording Policy: app.policy.read / app.policy.write (app.policy.delete to delete).
  • File Transfer Policy and file stores: app.policy.read / app.policy.write (app.policy.delete to delete).
  • Fact Policy and Fact Checks: app.fact_policies.read / app.fact_policies.write; viewing compliance results uses app.fact_policies.execute.
  • Config Policy: app.configure.read / app.configure.write (app.configure.execute to use the resource Configure tab, render, preview and push).
  • Syslog Policy: app.collector.read / app.collector.write.
  • IDS Policy: app.sensors.read / app.sensors.write.