> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Policy



## OpenAPI

````yaml /api-reference/openapi.json post /api/runtime-security/dlp/policies
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/runtime-security/dlp/policies:
    post:
      tags:
        - dlp-admin
      summary: Create Policy
      operationId: create_policy_api_runtime_security_dlp_policies_post
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DlpPolicyCreate'
      responses:
        '201':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    DlpPolicyCreate:
      properties:
        name:
          type: string
          maxLength: 128
          minLength: 1
          title: Name
        description:
          anyOf:
            - type: string
              maxLength: 500
            - type: 'null'
          title: Description
        bundle:
          $ref: '#/components/schemas/DlpPolicyBundle'
      type: object
      required:
        - name
      title: DlpPolicyCreate
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    DlpPolicyBundle:
      properties:
        fail_mode:
          anyOf:
            - type: string
              pattern: ^(open|closed)$
            - type: 'null'
          title: Fail Mode
        host_rule_overrides:
          anyOf:
            - items:
                additionalProperties: true
                type: object
              type: array
            - type: 'null'
          title: Host Rule Overrides
        agentic:
          anyOf:
            - $ref: '#/components/schemas/DlpAgenticOverride'
            - type: 'null'
        privacy_mode:
          anyOf:
            - type: string
              pattern: ^(redacted_only|both_role_gated)$
            - type: 'null'
          title: Privacy Mode
      type: object
      title: DlpPolicyBundle
      description: |-
        The settings bundle a policy carries. Every field optional → inherit.

        Mirrors the override-able subset of ``RuntimeSecurityConfig``. ``None``
        means "no opinion"; the resolver only merges keys that are set.
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
    DlpAgenticOverride:
      properties:
        tool_allowlist:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Tool Allowlist
        tool_denylist:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Tool Denylist
        max_arg_bytes:
          anyOf:
            - type: integer
              maximum: 1000000
              minimum: 256
            - type: 'null'
          title: Max Arg Bytes
        allow_private_network:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Allow Private Network
      type: object
      title: DlpAgenticOverride
      description: Sparse agentic override, any unset field inherits from the merge base.

````