Overrides
An override is what Ploy records when a person deliberately contradicts a policy: they take away access a Gets policy grants, or they hand out access a Never gets policy forbids. This article explains how each policy reacts to that, and what your two choices are when one is surfaced to you.
What counts as an override
Ploy records an override only for a deliberate action someone took inside Ploy against a specific policy, one record per policy and piece of access. Two directions exist:
Access a Gets policy grants was manually taken away.
Access a Never gets policy forbids was manually granted or kept.
Drift picked up by a scanner is never recorded as an override. Neither is anything on a Can request, Can't request or Remove when unused policy, because none of those hold access of their own.
Manual overrides: what each setting does
Every granting or denying policy carries a Manual overrides setting, chosen in the builder:
Setting | What Ploy does |
|---|---|
Reverse | Ploy puts it back the way the policy says, and shows you what happened. |
Flag (the default) | The change stands. Ploy shows it to you for review. |
Log | The change stands. Ploy records it in history and tells nobody. |
The setting a policy had at the moment the override was spotted is the one that applies to that record, even if you change the setting afterwards.
Reviewing an override
Look for the amber "{N} awaiting review" chip on a policy card. It appears while that policy has overrides you have not decided.
Open the policy and go to its Overridden tab. The tab is only offered when there is something in it.
Read the row. The tab explains itself: "Access that someone changed by hand, against this policy. Restore puts it back the way the policy says; exempt keeps the manual change and stops the policy managing that pair."
Choose one of two buttons:
Restore access re-applies the policy, putting the access back the way the policy says.
Exempt from policy keeps the manual change and stops the policy managing that person and that app.
Once decided, the row reads "Access restored" or "Exempted from policy" as plain text.
If nobody has contradicted the policy, the tab is absent and the equivalent message elsewhere reads "No manual overrides. Nobody has contradicted this policy by hand."
Good to know
Restore is not finished when you click it. The row stays surfaced until the grant or removal actually lands in the app, not merely once Ploy has asked for it. If the access turns out to be gone already, Ploy treats the removal as done.
Exempt is permanent. It is the one terminal choice here. Ploy will never reopen an exempted row by itself, even if a late result from an earlier restore arrives afterwards.
Log is genuinely silent. A policy set to Log records overrides for history and never shows them to anyone, so the Overridden tab stays empty and no chip appears.
Reverse still shows you the drift. The record is surfaced until the automatic re-application resolves it, so Reverse is not a way to make contradictions invisible.
Overridden is its own slice of your coverage. Access someone granted or kept by hand against a policy is counted as Manually overridden in the coverage ledger, deliberately separate from Unexplained. The ledger row reads "Manually granted despite {policy}" with the name of the person who did it.
Manual overrides and enforcement are two different settings. Enforcement decides how strongly Ploy acts on its own findings. Manual overrides decide how Ploy reacts to a person contradicting it. A policy can suggest quietly and still reverse manual changes, or the other way around.
You may be told an override is already settled. If someone decided it between your opening the tab and clicking, Ploy answers "This override has already been resolved."