Safety & Security · Data artifact
Policy Enforcement Mode Configuration
Data artifactSafety & SecuritySafety, Security & GovernanceVariation point (abstract)arc:PolicyEnforcementModeConfig
An abstract configuration setting, per policy, whether the policy engine only logs evaluation outcomes, blocks violations, or blocks and launches automated remediation.
Responsibility. Determines the enforcement strength the policy engine applies to each policy.
Also known as: Progressive enforcement phase
Variants
| Variant | When to choose |
|---|---|
| Full Enforcement Mode | Choose once policies have been calibrated in monitor and soft modes and their thresholds reflect organizational reality. |
| Monitor-Only Enforcement Mode | Choose when first deploying policies, to observe agent behaviour, detect over-triggering or never-triggering policies, and calibrate thresholds before enforcement. |
| Soft Enforcement Mode | Choose after baseline calibration when severe-consequence, low-error-tolerance policies (production database deletion, SSN exfiltration, exceeding authority limits) must be enforced while other policies still need tuning. |
Relationships
configures structural
Design guidance
- SHOULD introduce enforcement progressively (monitor, then soft, then full) so thresholds are calibrated to observed behaviour before blocking.
Classification
- Patterns
- Progressive enforcement
- Quality attributes
- Maintainability (ISO/IEC 25010)Safety (ISO/IEC 25010 | NIST AI RMF: safe)
- Risks mitigated
- Operational disruption from activating all policies at full enforcement on day one
Sources
- Ch10.5: T. Nguyen, "Human-over-the-Loop," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 10.5. ISBN: 9798244538229.