Policy Precedence

Policy Precedence

WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Welcome
Supported Applications & LLMs
Release Notes
August 18, 2026 WitnessAI Release
August 4, 2026 WitnessAI Release
July 21, 2026 WitnessAI Release
July 14, 2026 WitnessAI Release
July 9, 2026 WitnessAI Release
June 30, 2026 WitnessAI Hotfix
June 23, 2026 WitnessAI Release
June 16, 2026 WitnessAI Release
June 11, 2026 WitnessAI Release
June 4, 2026 WitnessAI Hotfix
June 2, 2026 WitnessAI Update
May 19, 2026 WitnessAI Update
April 30, 2026 WitnessAI Update
April 28, 2026 WitnessAI Update
April 23, 2026 WitnessAI Update
April 16, 2026 WitnessAI Update
April 14, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 7, 2026 WitnessAI Update
April 2, 2026 WitnessAI Update
March 31, 2026 WitnessAI Update
March 24, 2026 WitnessAI Update
March 19, 2026 WitnessAI Update
March 17, 2026 WitnessAI Update
March 12, 2026 WitnessAI Update
March 5, 2026 WitnessAI Update
February 26, 2026 WitnessAI Update
February 24, 2026 WitnessAI Update
February 10, 2026 WitnessAI Update
January 27, 2026 WitnessAI Update
January 20, 2026 WitnessAI Update
January 13, 2026 WitnessAI Update
December 18, 2025 WitnessAI Update
December 9, 2025 WitnessAI Update
November 25, 2025 WitnessAI Update
November 18, 2025 WitnessAI Update
November 11, 2025 WitnessAI Update
October 28, 2025 WitnessAI Update
October 23, 2025 WitnessAI Update
October 9, 2025 WitnessAI Update
October 2, 2025 WitnessAI Update
September 30, 2025: WitnessAI Update
September 23, 2025: WitnessAI Update
August 12, 2025: WitnessAI Update
July 31, 2025: WitnessAI Update
July 18, 2025: WitnessAI Update
April 11, 2025: WitnessAI Release v2.0
June 9, 2025: WitnessAI Update
June 23, 2025: WitnessAI Update
TOC Left Sidebar: not active
TOC Left Sidebar: ORIGINAL
User Guide
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
404

Policy Processing

WitnessAI employs a “first-match” or “top-down” policy processing approach.
In this approach, User Prompts and Model Responses are checked by each Policy in the order Policies are listed on the Policy console, from top to bottom.
The first, or top-most Policy that matches the Prompts, and the combination of Policy and GuardRail attributes such as: Source (Users and/or Groups), Destination (Providers, Applications, Models, and/or Lists), Prompt, Intent, Behavior, and Response (in the case of the Harmful Response Prevention Guardrail), will perform the GuardRail Actions configured in the Policy.
After the first match, the User Prompt will not be checked by any more policies in the list.
This is why the Global Block Policy (GBP) is pinned to the top of the Policy list. Any AI service that is on the Blocked Apps List will be automatically added to the GBP and all traffic will be blocked. Since the traffic will be blocked, no further Policies and GuardRails will be applied.
The Attachment Block Policy (ABP) is pinned just below the GBP. Full ABP details are on the File Attachment page.
 
WitnessAI Policies list showing the Policy Precedence concept. The list displays 5 policies in order: (1) Global Block Policy - Blocked Apps list - Block action; (2) Chat Client Automation - GitHub Default - Model Protection +1 more - Allow/Warn - enabled; (3) Krishna-Test policy - Testing basic prompts - kr-krib +1 more - Model Identity Protection - Allow - enabled; (4) karan forticlient - Organizational Behavior +1 more - Warn - enabled; (5) Seth’s Fortinet Block Policy - sethq - Harmful Response Prevention (Beta) +1 more - Block - disabled.
 
WitnessAI Policy editor showing the ‘Krishna-Test policy’ Details tab, General section. Fields shown: Name (Krishna-Test policy), Description (Testing basic prompts), Policy Type (Guardrail). Right panel shows Action: Allow, GuardRail: Model Identity Protection, Sources: krishna@plaped, Destinations: OpenAI-gpt-4o, OpenAI-gpt-4.0-turbo, OpenAI-o1-preview, OpenAI-o1-mini.
 
WitnessAI Policy editor showing the ‘Krishna-Test policy’ Details tab, Assignments section. Shows ‘Select Sources and Destinations’ with Source (IT, Users, Is any of these: krishnavasudeva@witness.ai) and Destination (IT, Models, Is any of these: OpenAI-gpt-4o, OpenAI-gpt-3.5-turbo, OpenAI-o1-preview, OpenAI-o1-mini). THEN clause shows ‘The enabled GuardRails will be applied’.
 
WitnessAI Policy editor showing the ‘Krishna-Test policy’ GuardRails tab with ‘Model Identity Protection’ GuardRail enabled. Shows Model (Private Model: hosted_v5m/cognitive), System Prompt (Toyota 4Runner-based chatbot instructions), Enable Response Protection toggle, Allowlist, Message (’Sorry - I’m unable to help with that.’), Behavior section with Input behaviors, ‘Recommend Toyota’ tag, and Action: Allow.