Skip to content

docs: add Application Control extension page - #473

Closed
pllesperance-lc wants to merge 2 commits into
masterfrom
docs/app-control
Closed

pllesperance-lc wants to merge 2 commits into
masterfrom
docs/app-control

Conversation

@pllesperance-lc

Copy link
Copy Markdown
Contributor

Adds a page for the Application Control extension (ext-app-control), at 5-integrations/extensions/limacharlie/app-control.md, linked from the nav and the LimaCharlie extensions index.

Supported only on endpoint agent 5.4.0 and later. This is stated in a warning right after the overview, in Requirements, and in the index entry.

Sections:

  • Overview and scope: decisions are made before the process starts, with an allowlist or blocklist stance. It covers process execution only, for new processes only, on Windows and macOS only.
  • Requirements: agent 5.4.0+, the Windows kernel driver, and macOS 11+ with the system extension.
  • How a decision is made: the fixed precedence order, OS-vendor trust, and allow-on-unresolved behaviour.
  • Modes: off, permissive, permissive_sync, enforcing.
  • Configuring policies: targeting, the policy document, rule kinds and matching details.
  • Examples: a Windows allowlist, a macOS allowlist, a blocklist, and a staged-rollout YAML config.
  • Rollout procedure and points to watch.
  • Configuration via Hive: the CLI hive get/validate/set commands.
  • Verifying the applied policy: the app_control_policy reply, status fields, and all APP_CONTROL_DEGRADED flags.
  • Events: APP_CONTROL_DENIED, APP_CONTROL_UNRESOLVED, APP_CONTROL_POLICY_REP, with fields and reason codes.

Open items before merging:

  • The agent 5.4.0 release is not out yet. The latest published release notes are for 5.3.12.
  • The marketplace URL (…/extension-detail/ext-app-control) is assumed from the DLP pattern.
  • A fix for the 14-day policy expiry is in progress in lc_sensor. Today an enforcing host drops to permissive 14 days after the last policy change, because an unchanged policy is not re-pushed. The POLICY_STALE row may need updating once that fix lands.

🤖 Generated with Claude Code

pllesperance-lc and others added 2 commits October 1, 2026 17:57
Document the ext-app-control extension: pre-execution allow/deny by
path, signer, signing ID, signer root or SHA-256 on Windows and macOS,
with permissive, permissive_sync and enforcing modes. Covers decision
order, policy document and rule kinds, examples, staged rollout,
hive/CLI configuration, the app_control_policy command, status and
degraded flags, and the APP_CONTROL_* events.

Supported on endpoint agent 5.4.0 and later only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…re by default

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@limacharlie-refractionpoint

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation b35a23a…6014a04 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb

maximelb commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Heads-up: #481 just merged a page at docs/5-integrations/extensions/limacharlie/app-control.md, plus Config Hive pages for app_control_policy and app_control_rule and the APP_CONTROL_* events. Application Control policies now live in those two hives. The extension's pasted-JSON configuration is gone, so this PR's configuration section is out of date, and the PR now conflicts on app-control.md and the extension index.

The sensor-side material here isn't covered by #481 and would be worth folding into the merged page: APP_CONTROL_POLICY_REP, the APP_CONTROL_DEGRADED flags, reason codes and policy age.

🤖 Generated with Claude Code

@maximelb

maximelb commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Closing as superseded by #481, which documents the current hive-based Application Control configuration. The sensor-side details in this PR could still be added to the merged page in a follow-up PR: APP_CONTROL_POLICY_REP, the APP_CONTROL_DEGRADED flags, reason codes and policy age. The branch is left in place so they can be reused.

@maximelb maximelb closed this Oct 4, 2026
@pllesperance-lc
pllesperance-lc deleted the docs/app-control branch October 6, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants