Skip to main content

Rules

Workshop provides comprehensive rule management for controlling system behavior across your organization. Rules define policies for execution control, file access authorization, and network flow authorization.

Rule Categories

Execution Rules

Control which binaries can execute on your systems. Execution rules use Santa's binary authorization capabilities to allow or block applications based on cryptographic signatures, certificates, and other identifiers.

Learn more about Execution Rules →

Execution rules can also carry a CEL program that decides allow/block dynamically based on execution context.

Read the Complete Guide to CEL in Santa Rules →

Sandbox Rules

Require a binary to be launched under santactl sandbox with a macOS Seatbelt (SBPL) profile attached, so it runs confined instead of being simply allowed or blocked. Requires Santa 2026.6+.

Learn more about Sandbox Rules →

File Access Rules

Regulate which processes can read and write files on macOS systems. File Access rules provide fine-grained control over file system access, enabling monitoring, logging, and blocking of access attempts.

Learn more about File Access Rules →

Network Rules

Authorize, deny, or audit network connections on macOS hosts. Network rules match connections by local process, remote peer, and transport (ports, protocols, direction), using Santa's network extension. Requires the network extension tenant feature.

Learn more about Network Rules →

Package Rules

Target software by name in a package catalog and let Workshop materialize execution rules for it, kept in sync as new versions ship. Optional CEL filters narrow a rule down to specific versions and binaries.

Learn more about Package Rules →

Rule Packs

Subscribe a tag to a curated set of rules maintained by North Pole Security. Each pack's rules are materialized into ordinary, editable Workshop rules and kept in sync as the pack is updated.

Learn more about Rule Packs →