Apply a deployment
- Dashboard
- CLI
- Go to Admin → enforcement, find the machine, and expand its row.
- Select edit, add the reviewed policy version, and choose observe or its enforcing effect.
- Apply the change, then wait for the machine’s next check-in and confirm its deployment and coverage state.
-
Go to Observe → policy to inspect live decisions.

1
Choose the version and targets
Deploy a reviewed version, not a mutable draft, starting with a non-production machine or small cohort whose sessions you can inspect.
2
Observe decisions
Review matches, reasons, affected tools, and false positives without blocking work.
3
Enforce and verify coverage
Promote after observed matches separate unsafe actions from valid ones, then confirm every intended machine has pulled the deployment and is reporting decisions.
policies:pull capability. Event reporting is separately controlled by events:add; verify both when you expect Cloud analysis and enforcement.

