Product GuidesstableUpdated 2026-05-15

Guardrails — Exceptions

Create, submit, inspect, duplicate, and revoke temporary governance exceptions.

What this page is for

Exceptions manages temporary bypasses or special allowances. It makes the target, scope, time window, risk level, justification, compensating controls, approval state, and revocation history clear.

Who uses it

  • Admins
  • Finance owners
  • Security reviewers
  • Platform operators

What you see

  • List with target, status, exception type, risk level, scope, requester, start/end dates, and approval summary.
  • Filters for search, status, type, includeExpired, and temporal state when available.
  • Detail sheet with target, scope, risk, timeline, approval link, justification, revoke info, snapshots JSON, and extension lineage.
  • Editor covering target, scope, time window, risk, justification, compensating controls JSON, and extensionOfExceptionRequestId.

What you can do

  • Create a draft exception.
  • Edit a draft.
  • Submit a draft for approval.
  • Duplicate an exception into a new draft.
  • Revoke an active exception with a reason.
  • Open the linked approval.

Permissions and safety

  • Draft editing is limited to draft status.
  • Revocation should require the exception to be active.
  • Risk and compensating controls should be visible before submission.

Operational notes

  • The editor should validate JSON live and make compensating controls readable.
  • The detail sheet acts as the audit-oriented view.

What this page is not for

  • Changing cap definitions.
  • Changing approval chain templates.
  • Replacing audit integrity.
  1. Confirm that you are in the right workspace and environment.
  2. Use filters before changing configuration or interpreting results.
  3. Open the detail drawer when available.
  4. Check related objects such as alerts, approvals, costs, policies, runs, deliveries, or audit entries.
  5. Apply changes only when the impact is clear.
  6. Re-check the page after the backend refreshes.
  7. Export or copy IDs when you need to escalate.