Safety & Security · Data artifact

Policy Enforcement Mode Configuration

Data artifactSafety & SecuritySafety, Security & GovernanceVariation point (abstract)arc:PolicyEnforcementModeConfig

An abstract configuration setting, per policy, whether the policy engine only logs evaluation outcomes, blocks violations, or blocks and launches automated remediation.

Responsibility. Determines the enforcement strength the policy engine applies to each policy.

Also known as: Progressive enforcement phase

configuresis specialized byis specialized byis specialized byAction Policy Engine: configuresAction Policy EngineFull Enforcement Mode: is specialized byFull Enforcement ModeMonitor-Only Enforcement Mode: is specialized byMonitor-Only Enforcement…Soft Enforcement Mode: is specialized bySoft Enforcement Mode
Direct neighbourhood (hover for relationship types)

Variants

VariantWhen to choose
Full Enforcement ModeChoose once policies have been calibrated in monitor and soft modes and their thresholds reflect organizational reality.
Monitor-Only Enforcement ModeChoose when first deploying policies, to observe agent behaviour, detect over-triggering or never-triggering policies, and calibrate thresholds before enforcement.
Soft Enforcement ModeChoose after baseline calibration when severe-consequence, low-error-tolerance policies (production database deletion, SSN exfiltration, exceeding authority limits) must be enforced while other policies still need tuning.

Relationships

configures structural

Design guidance

Classification

Patterns
Progressive enforcement
Quality attributes
Maintainability (ISO/IEC 25010)Safety (ISO/IEC 25010 | NIST AI RMF: safe)
Risks mitigated
Operational disruption from activating all policies at full enforcement on day one

Sources

  1. Ch10.5: T. Nguyen, "Human-over-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.5. ISBN: 9798244538229.