Policies & issues
Policies govern how AI is used across your environment. When an asset violates a policy, Evo raises an issue that you triage and resolve in your standard security workflow.
Policies
A policy has a name, a severity (Critical, High, Medium, or Low), one or more conditions matched against asset attributes, and optional remediation steps. A policy supports up to 12 conditions, one per attribute.
Create and edit policies from the Policies & issues page or with Evo chat. You can delete custom policies. Default policies are read-only.
Default policies
Evo provides default policies that raise high or critical severity risks as issues with no setup. AI-SPM and Agent Supply Chain Security each include default policies.
User-defined policies
You can also create custom policies. With custom policies, you target assets by their attributes — for example, disallow a specific model in your code, or disallow a specific MCP server in your code, on end users' machines, or both.
Create a policy
You can create a policy from the Policies page or using Evo chat.
Create a policy from the Policies page
To create a policy from the Policies page:
Click Create policy.
Complete the form fields.
Use the dropdown menus to select an attribute, a condition, and a value.
Click +Add condition to add another condition to the same policy. You can create up to 12 conditions, one per attribute.
Click Create.
Create a policy using Evo chat
To create policies using Evo chat, you can ask it to create a policy with specific criteria. For example, you can ask it to "create a policy that raises a critical issue when you detect [model name]".
The Policy agent then navigates to the policy creation form. Ensure the policy details are correct and click Create to create the policy.
Based on the policy, Evo evaluates scan results and creates issues when matches occur.
A newly created policy produces issues immediately after creation.
Edit a policy
From the Policies page, select the policy you want to edit and click Edit policy. The following fields are available:
Policy name
The name of the policy.
Severity
The severity level assigned to issues created by this policy: Critical, High, Medium, or Low.
Conditions (match all)
Add a condition for assets under the policy.
Use the dropdown menus to select an attribute, a condition, and a value.
Click +Add condition to add another condition to the same policy. You can create up to 12 conditions, one per attribute.
Remediation steps (optional)
Add remediation advice.
Delete a policy
You cannot delete default policies.
You can delete user-defined policies. To quickly identify critical enforcement, you can group policies by severity.
To delete a policy:
Select the policy you want to delete.
Click the ellipsis next to Edit policy.
Click Delete.
Issues
An issue is a policy violation. View issues on the Policies & issues page under Issues, or on an asset in Inventory to see them in context.
Each issue shows its severity, the asset that triggered it, remediation advice, and the number of occurrences. The remaining details vary by issue type.
Last updated
Was this helpful?

