Govern
Govern is where you set the rules MisterShell enforces at runtime across your estate. It is a top-level area in the main navigation (the page itself is titled Policies), and it groups every policy engine on one page as a set of tabs. Each governs a different stream of activity, and most are ordered lists of rules evaluated top to bottom, first match wins:
| Policy | Governs | On a match it can… | Edition / add-on |
|---|---|---|---|
| Session Policy | Interactive sessions — both when a session opens and each command typed in a shell | Accept or Deny (and optionally notify / log) | Enterprise |
| Recording Policy | Interactive sessions, at connection time | Record or Skip, choosing the store and retention | Enterprise |
| File Transfer Policy | Copies between the file catalog and compatible resources | Accept or Deny (and optionally notify / log) | Enterprise |
| Fact Policy | The collected facts about each resource | Mark a resource pass / fail against a compliance rule | Enterprise |
| Config Policy | Device configuration | Bind a configuration stack to matching resources, to render and push | Enterprise |
| IDS Policy | Each intrusion-detection alert your sensors raise | Any combination of Notify and Log, or Suppress | IDS Sensors add-on |
| Syslog Policy | Each device log record your collectors ingest | Any combination of Log, Notify, and Forward, or Discard | Syslog Collector add-on |
The edition / add-on column describes what your license must include to make changes and have the policy take effect — it never hides anything. Which tabs you see is decided purely by your role’s permissions (below). Without the required entitlement, the create/edit buttons on a tab show a lock, and the Enterprise-gated policies also stop acting: session rules are not enforced (neither at connection nor per command), sessions are not recorded, and fact rules are not evaluated. Definitions and previously collected evidence always remain visible.
Config Policy works a little differently from the rest: rather than reacting to a stream of activity, you author configuration templates and stacks and bind them to resources, then render and push them from each resource’s Configure tab.
Two of the policies reference a reusable building block, kept in its own sub-view of the same tab (a Rules / ACLs or Rules / Checks toggle in the tab’s toolbar) so it can be maintained once and referenced by many rules:
- Session ACLs — named sets of command patterns that Session Policy rules match against (for example a shared “read-only SQL” or “dangerous shell commands” set).
- Fact Checks — named sets of assertions that Fact Policy rules evaluate (for example “NTP synchronized,” “no Telnet listener”).
How the policies fit together
Each policy is an independent, ordered decision chain over its own input stream. They share the same evaluation model but never interfere with one another:
flowchart LR
sess["Interactive session<br/>connection · each command"]
facts["Collected facts"]
logs["Ingested device logs"]
alerts["IDS alerts"]
subgraph govern["Govern · runtime policy engines"]
direction TB
sp["Session Policy<br/>accept / deny"]
rp["Recording Policy<br/>record / skip"]
fp["Fact Policy<br/>pass / fail"]
syp["Syslog Policy<br/>log / notify / forward / discard"]
ip["IDS Policy<br/>suppress / notify / log"]
end
sess --> sp
sess --> rp
facts --> fp
logs --> syp
alerts --> ip
sp -. "notify / log" .-> out["Automation events ·<br/>Policy Log · your SIEM"]
fp -. "compliance change" .-> out
syp -. "notify / forward" .-> out
ip -. "notify / log" .-> out
A Notify action on any policy raises an automation event, so you can wire alerts, emails, or webhooks to policy decisions. Session Policy decisions with Log on are also written to the Policy Log audit trail, and Fact Policy results feed the Compliance heatmap.
Permissions
Policy selectors show location paths, tag names, role names and sensor names across the estate where those selectors apply. Reading the relevant policy is sufficient to see these choices; it does not grant access to the resources, role membership, sensor operation or credentials behind them. Policy hit counters also remain global.
Each tab is shown or hidden independently by your role’s read permission — you see only the policies your role allows (the license, by contrast, only locks changes; it never hides a tab):
- Session Policy, Session ACLs, and Recording Policy:
app.policy.read/app.policy.write(app.policy.deleteto delete). - File Transfer Policy and file stores:
app.policy.read/app.policy.write(app.policy.deleteto delete). - Fact Policy and Fact Checks:
app.fact_policies.read/app.fact_policies.write; viewing compliance results usesapp.fact_policies.execute. - Config Policy:
app.configure.read/app.configure.write(app.configure.executeto use the resource Configure tab, render, preview and push). - Syslog Policy:
app.collector.read/app.collector.write. - IDS Policy:
app.sensors.read/app.sensors.write.