Skip to main content
Help Center

Configure and Apply a Security Policy Gate in Guard

Turn release-specific Guard findings and policy thresholds into an explicit pass, block, or authorized exception.

Guide navigation 26 of 42
Browse all 42 articles
Business view

What this page helps you accomplish

Turn release-specific Guard findings and policy thresholds into an explicit pass, block, or authorized exception.

Batoi Platform · Guard
Accountable roleSecurity Owner, Release Owner, Reviewer
Business taskPolicy Management
Completion signalThe release gate enforces reviewed conditions, stops unsafe promotion, and preserves the evaluated result and any authorized exception.
1 Confirm

Scope and authority

A selected app and release with current Guard checks and findings Authority to define blocking thresholds and decide or escalate exceptions

2 Act

Policy Management

Turn release-specific Guard findings and policy thresholds into an explicit pass, block, or authorized exception.

3 Verify

Observable business result

The release gate enforces reviewed conditions, stops unsafe promotion, and preserves the evaluated result and any authorized exception.

Potential issue and recovery

The expected record or action is missing.

Recommended recovery: Return to the intended context and ask an Owner or Admin to confirm access. Do not use another person’s account.

Who should use this article

This article is for Security Owner, Release Owners, and Reviewers who are authorized to complete or review this task. A consequential decision remains with the accountable person.

Before you begin

  • A selected app and release with current Guard checks and findings
  • Authority to define blocking thresholds and decide or escalate exceptions
  • An evidence owner for the release result
  • Use approved sample or operational information only. Never enter a password, token, private key, or unnecessary personal information.
An Active gate is not a Passed evaluation. Run and record a release-specific Guard result before promotion.

Open Guard review and the gate

  1. Open the selected app in Build.
  2. Expand Review & Assurance and choose Guard Checks & Findings.
  3. Review the relevant findings, then open Guard Gate.
Guard release gate workflow Release-specific checks produce findings, policy thresholds evaluate those findings, and the gate passes, blocks, or records an authorized time-bounded exception. Convert findings into a controlled release decision Release Checks Source, dependency, exposure, and runtime Policy Thresholds Severity, ownership, evidence, and expiry Gate Result Passed, Failed, or authorized exception Evidence Decision, owner, reason, and follow-up
A release gate must preserve both the evaluated facts and the human decision.

Review the current posture

  1. Filter checks and findings to the relevant application, repository, release, environment, and severity.
  2. Confirm Critical and High findings are resolved or explicitly blocked.
  3. Review Medium findings that affect traceability, pipeline ownership, deployment manifests, or architecture.
  4. Separate workspace-wide posture from the release-specific result. A good workspace score does not automatically approve this release.
Batoi Guard Checks and Findings
Reference screen: the Guard board explains current posture and remaining gaps, but the release still needs its own gate evaluation.

Configure and apply the gate

  1. Bind the gate to the selected app and release object.
  2. Define required checks, blocking thresholds, evidence freshness, and accountable owner.
  3. Require a blocking result for unmet release conditions.
  4. Define the exception authority, reason, expiry, compensating action, and follow-up evidence.
  5. Run the release-specific evaluation and record Passed, Failed, or Waived only from the evaluated outcome.

Completion check

  • The gate is scoped to the intended app, release, and environment.
  • Critical and High release blockers are absent or stop promotion.
  • Medium app-relevant findings have an owner and due action.
  • Any exception is authorized, time-bounded, justified, and preserved as evidence.
  • The result is linked to the deployment and governance evidence.

Troubleshooting and recovery

What you seeWhat to checkSafe next action
The expected record or action is missing.Workspace, project/app context, role, status filters, and prerequisites.Return to the intended context and ask an Owner or Admin to confirm access. Do not use another person’s account.
The status remains incomplete or needs review.Required fields, evidence, approvals, source connections, checks, and owners.Record the missing item and owner. Do not mark the task complete until it can be independently verified.
The result conflicts with policy or evidence.Scope, source recency, exception authority, decision conditions, and reviewer independence.Do not bypass the control. Return the item for correction or escalate it through the authorized route.

Safety and governance

Protect sensitive information. Do not place credentials, secrets, private keys, raw tokens, unnecessary personal information, private repository content, customer identifiers, or restricted documents in a public note, screenshot, prompt, export, or evidence caption. Use approved secret references and permission-controlled workspace records.

Final verification

Expected result: The release gate enforces reviewed conditions, stops unsafe promotion, and preserves the evaluated result and any authorized exception.

Next step

Continue with the next verified article in this Product Guide, or return to the Batoi Platform Product Guide.