Docs

Policy Activity

Review policy execution, frequently triggered rules, inactive rules, and governance outcomes.

Policy Activity reads decision outcomes rather than raw invocations — its source is gcdm_decision_logs, the record of what Policy Evaluation actually decided for each call, not the calls themselves. It is the operational counterpart to Policy Management: that capability is where rules are authored, this is where their real effect in the window gets checked.

The summary counts total evaluations split by effect — allow, deny, warn, audit — plus a separate implicit_deny count: denies where the decision log's matched_rules array is empty, meaning no authored rule actually matched and the call was denied by default. That number is a governance-gap signal distinct from ordinary rule-driven denies.

Top firing rules unnests every matched rule across all decision logs in the window and ranks the ten that fired most often, along with how many distinct subjects each one affected — the rules doing the most real work. Inactive rules is the opposite list: published rules that never matched a single call in the window, surfaced as plain badges so an operator can spot policies that may be misconfigured, unreachable, or simply not yet relevant to observed traffic.

Reference