> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Upsert Device Rule

> Add or edit a rule for this device alone.

Using an existing workspace rule's name replaces it here, which is a way of
weakening the company's own floor on this machine and so needs
``rules.override_workspace`` on top of the ordinary grant. So does using
the name of a detector the agent ships: the agent merges by name, so a row
called ``credit_card`` replaces card detection on this endpoint even though
no workspace row exists to compare it against.

Neither check reads ``enabled``, and that is the point. A row that says
``enabled: true`` and carries a pattern matching nothing removes the
detector exactly as thoroughly as ``enabled: false`` does, while every
surface -- the rules tab, the policy payload, the audit record -- reports
the rule as on. Any gate phrased in terms of ``enabled`` misses that.



## OpenAPI

````yaml /api-reference/openapi.json put /api/runtime-security/agent/rules/{name}
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/runtime-security/agent/rules/{name}:
    put:
      tags:
        - runtime-security-agent
      summary: Upsert Device Rule
      description: >-
        Add or edit a rule for this device alone.


        Using an existing workspace rule's name replaces it here, which is a way
        of

        weakening the company's own floor on this machine and so needs

        ``rules.override_workspace`` on top of the ordinary grant. So does using

        the name of a detector the agent ships: the agent merges by name, so a
        row

        called ``credit_card`` replaces card detection on this endpoint even
        though

        no workspace row exists to compare it against.


        Neither check reads ``enabled``, and that is the point. A row that says

        ``enabled: true`` and carries a pattern matching nothing removes the

        detector exactly as thoroughly as ``enabled: false`` does, while every

        surface -- the rules tab, the policy payload, the audit record --
        reports

        the rule as on. Any gate phrased in terms of ``enabled`` misses that.
      operationId: upsert_device_rule_api_runtime_security_agent_rules__name__put
      parameters:
        - name: name
          in: path
          required: true
          schema:
            type: string
            title: Name
        - name: X-Blindsight-Device-Token
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Blindsight-Device-Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DeviceRuleUpsert'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    DeviceRuleUpsert:
      properties:
        name:
          type: string
          maxLength: 64
          title: Name
        pattern:
          type: string
          maxLength: 512
          title: Pattern
        label:
          anyOf:
            - type: string
              maxLength: 64
            - type: 'null'
          title: Label
        flags:
          anyOf:
            - type: string
              maxLength: 8
            - type: 'null'
          title: Flags
          description: Regex flag letters, e.g. 'i'
        enabled:
          type: boolean
          title: Enabled
          default: true
      type: object
      required:
        - name
        - pattern
      title: DeviceRuleUpsert
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````