Introducing Agent Policies and Agent Shifts: Control What Agents Investigate and When

Reviewed by ContraForce team · Updated 2026-09-14

We have released Agent Policies and Agent Shifts to give your team more control over Security Delivery Agents. You can now define which incidents an agent may investigate and set the weekly hours when it investigates automatically. Together, these features help MSPs, MSSPs, and security teams make agent behavior match the way they deliver security services.

Some incidents need to stay with your analysts. Some workspaces need automatic investigations during a specific coverage window. These controls make those decisions explicit, with policy outcomes in the workspace audit trail and shift status visible in Agent Center.

Agent Policies: decide which incidents agents investigate

Agent investigation policies determine whether an agent is allowed to investigate an incident. Build allow or block rules using incident conditions such as the people or devices involved, the title, severity, or source. Investigation policies have two outcomes: allow or block. They do not offer an approval step.

Workspace Owners manage the list from the Agents tab in workspace settings. That same workspace list appears on each agent’s Policies tab. An edit in either location updates the same rules, so you do not need to maintain separate copies.

Rules are evaluated from top to bottom, and the first matching policy decides the outcome. If no policy matches, the investigation is allowed. Put narrow exceptions above broader restrictions, and use the ordering controls to make that intent clear. You can also disable a policy without deleting it.

When a policy blocks an automatic investigation, the incident remains in your team’s queue and the decision is recorded in the workspace audit trail. When it blocks a manually requested investigation, the person who requested it sees a message identifying the policy.

Agent Shifts: set the hours for automatic investigations

Agent Shifts give Workspace Owners a weekly grid for drawing working hours. Click individual hours or drag across a range, then choose the schedule’s timezone. The editor starts with Monday through Friday, 09:00 to 17:00. You can adjust those hours to fit your team’s coverage.

The selected timezone keeps the schedule aligned with local working hours through daylight saving changes. Agent Center shows On shift or Off shift for operational agents with shifts, with more detail about the schedule and the next change. The status refreshes when you reload or revisit the page.

A shift limits when automatic investigations can start. It does not enable automatic processing or change which incident severities the agent is configured to process automatically.

How policies and shifts work together

A shift is a row in the investigation policy list, so ordering matters. An allow rule above a shift can permit a specific class of incidents to be investigated automatically outside the usual hours, provided the agent’s automatic-processing configuration also permits it. For example, a narrowly defined incident-title exception can sit above a weekday schedule.

When a shift prevents automatic pickup, the incident stays in the queue for your team. The skipped investigation is recorded in the audit trail. When working hours resume, the agent does not automatically return to those skipped incidents; your team remains responsible for them.

Your team can still request an investigation outside working hours. Shifts do not block manual requests, although other investigation policies can. This distinction lets you schedule automatic work while keeping people able to request help within the workspace’s rules.

Get started in your workspace

As a Workspace Owner, open your workspace in Workspace Manager and select Agents, or open an agent in Agent Center and select Policies. Use Add policy to create an investigation rule, or choose Add a shift to draw a schedule. Review the list order and the agent’s automatic-processing settings together.

For policy configuration and evaluation details, read the Agent Investigation Policies guide.

For scheduling and shift visibility, read the Agent Shifts guide.

Questions about setting up policies or shifts for your team? Contact us at support@contraforce.com. We are happy to help.

What is "Introducing Agent Policies and Agent Shifts: Control What Agents Investigate and When" about?

Decide which incidents Security Delivery Agents may investigate and schedule their automatic working hours with Agent Policies and Agent Shifts.