Guides · Access and governance
Policies
A policy applies governance rules, such as session recording, Just-In-Time approval or blocking file transfer, to many SSH hosts at once instead of one host form at a time. Use it when a rule should follow a group or a tag, like “every production host records”.
- SSH hosts
- Stored on this device
- About 10 minutes
How a policy works
A policy is three things: a scope (which hosts), a mode (how firmly), and a set of rules. When you connect to a host, MangoSSH finds every enabled policy whose scope matches it, works out one value per rule, and uses that value for the connection. Bastion hops and Scripts go through the same resolution, so they get the same answer.
| Setting | Options |
|---|---|
| Applies to | All SSH hosts, A group (picked from your SSH groups), or A tag (typed, for example prod or env:prod). Group and tag names must match exactly: a policy for tag env does not match a host tagged env:prod. |
| Mode | Default — a host may override. The policy supplies the value unless a host explicitly overrides that rule. Mandatory — locked on every host. The policy wins and the host form shows the control locked. |
| Enabled | Untick Active to switch a policy off without deleting it. A disabled policy matches no hosts. |
Each on/off rule has three choices in the editor: On, Off, or — no opinion —. Leave a rule on “no opinion” and the policy does not touch it at all, so the host's own setting (or another policy) decides.
Create a policy
Click Dashboard in the toolbar, then Policies in the sidebar.
Click + New policy. The editor opens below the Global section.
Give it a Name people will recognise on the host form, such as “Production”.
Choose Applies to and, for a group or tag, which one. Then choose the Mode.
Under Rules this policy sets, set only the rules you care about. Under Requirements this policy checks, tick Required for any requirement.
Click Save policy. The policies table shows it with its mode, scope and rule chips, and a count such as “12 hosts in scope · all compliant”.
Click any row in the table to edit that policy. Delete removes it after a confirmation, and hosts return to their own settings. Creating, changing and deleting policies are written to the audit log.
Rules a policy sets
These are written onto each host in scope at connect time. Except where noted, they are the same switches you would otherwise set on the host form.
| Rule | What it does |
|---|---|
| Require Just-In-Time approval | A connection needs an active, time-boxed grant first. See Just-In-Time access. This needs a Cloud Vault or Self Hosting Vault: without one, every host the rule covers is blocked, and the Policies page shows a warning saying so. |
| Always record the session | Every session on the host is recorded from the first byte, even when recording is off globally. |
| Follow the server sshd log | Server-side logins, failures and disconnects stream into the audit log. POSIX servers only. |
| Strict crypto | Modern algorithms only: no ssh-rsa, SHA-1 key exchange or CBC ciphers. |
| Key revocation list (KRL) | Path to an OpenSSH KRL. A certificate that matches a revoked entry is refused. It is checked against the certificate this device presents, so hosts that log in without a certificate are unaffected. Relative paths resolve from your home folder. |
| Maximum certificate lifetime | Caps the lifetime of certificates from the MangoSSH CA and from HashiCorp Vault SSH, written like 1h, 30m or 8h. It only ever shortens: a host already asking for a shorter lifetime keeps it. |
| Maximum key age (days) | Records the key age you expect. In this version the value is stored and shown on the policy, but nothing else acts on it yet. |
| Block file transfer (SFTP) | The Files pane, uploads and runbook file steps are refused for the host. |
| Block port forwarding | Local, remote and SOCKS forwards are refused, including saved forwards and RDP tunnelled through the host. |
| Block agent and X11 forwarding | Turns the host's agent forwarding and X11 forwarding off. Setting it to Off never turns forwarding on for a host that had it off. |
The three “Block” rules stop MangoSSH from doing the transfer. Anyone who has the host's password or key can still use another SSH client. When people must not be able to take a credential elsewhere, share the host through the PAM Broker instead, so the credential never reaches their device.
Requirements a policy checks
Two rules cannot be switched on from a policy, because each needs something only the host can provide:
- Require an MFA-capable login: the host's sign-in must prompt for a second factor. On the host's Authentication tab that means Interactive, or SSH Key with Key + Interactive Login.
- Require the PAM broker: the host must be set up through the PAM Broker wizard, which needs the password and the host key fingerprint.
So these are checked, not set. A host that falls short is non-compliant:
- The policies table shows “N non-compliant” in red next to the policy.
- Open the policy and the Compliance section lists each failing host and what it lacks, with a Fix… button that opens that host's form.
- Connecting still works. You get a warning toast first, for example “Policy Production requires MFA — this host uses password auth”, and the connection goes ahead. This holds under a mandatory policy too.
When several policies match
A host can be in scope of several policies: one for all hosts, one for its group, one for a tag. MangoSSH settles each rule separately:
Mandatory beats default, whatever the values are.
Within the same mode, the most restrictive value wins: On beats Off, the shorter certificate lifetime wins, the smaller key age wins. For the KRL path, which is a single file, the policy listed first in the table wins.
Then the host: if the winner is a default policy and the host has overridden that rule, the host's own value is used. A host can never override a mandatory policy.
For example, a default “All hosts” policy with recording Off and a default “Databases” tag policy with recording On leaves a database host recording. Make the “All hosts” policy mandatory and it would win instead.
What the host form shows
Open a host with Edit. Each control a policy governs shows the policy's value and a badge under it:
| State | Badge and meaning |
|---|---|
| Locked | “🔒 Set by policy Name (mandatory)”. The control is disabled. Change the policy or its scope to change it. |
| From a default | “Set by policy Name · override for this host”. Click override for this host to unlock the control and use the host's own value, then save the host. |
| Overridden | “Overriding policy Name · use policy value”. This host has opted out of that default. Click use policy value to go back. |
The governed controls are Prompt for Just-In-Time approval before connecting (Access tab), Strict mode (Advanced tab), the KRL path (Authentication tab, key sign-in only), and on the Session tab Always record sessions, Follow server sshd log, Block file transfer (SFTP) on this host and Block port forwarding on this host. The top of the Session tab also lists every policy applied to the host, mandatory first, with a Manage policies link.
Certificate lifetime, key age and the agent/X11 block have no control of their own on the host form. They still apply at connect time.
Saving a host keeps its own value for any policy-driven control you did not override, not the policy's value. Delete or narrow a policy and every host goes back to exactly what it had before.
The Global section
The top of the Policies page gathers fleet-wide switches that also appear elsewhere in the app. All but the first are stored on your vault server and apply to everyone in the vault, and only a vault admin can change them.
| Setting | Effect |
|---|---|
| Recording default | Record every SSH session by default. This device's default for session recording. A policy or a host can add recording on top, and nothing turns it off while this is on. |
| Ticket reference | Require a ticket reference on every JIT access request. The vault server rejects access requests without one. |
| Approval code | Require a one-time code to approve JIT access. Every approver needs an enrolled authenticator, set up under PAM Dashboard → Pending requests → Approval security. If some admins have none, MangoSSH warns before turning it on. The server needs MFA_MASTER_KEY; see Self-hosting the vault server. |
| Grant for broker | Require a JIT grant for brokered and shared access. No PAM Broker or browser-link ticket for a non-admin without an active grant for that host, and a ticket or link ends when the grant does. |
| Encrypted disk | Require an encrypted disk: Off, Warn or Block. See Device posture. |
| MangoSSH CA | A link to Settings → MangoSSH CA, where certificate issuance per role is managed. |
Without a Cloud Vault or Self Hosting Vault, only the recording default is shown, with a note that the rest need a vault server.
Worked example: record every production session
Say your production hosts are in an SSH group called Production. If you mark them with a tag instead, choose A tag in step 3.
Open Dashboard → Policies and click + New policy.
Name it Production recording.
Set Applies to to A group and pick Production.
Set Mode to Mandatory — locked on every host, so nobody can switch it off on one host.
Set Always record the session to On. Leave every other rule on — no opinion —.
Click Save policy. The row shows how many hosts are in scope.
Check one host: Edit → Session. Always record sessions is on, locked, and badged “🔒 Set by policy Production recording (mandatory)”.
Connect. The session is recorded from the first byte, and the recording appears under Dashboard → Session Logs.
New hosts added to the Production group are covered the moment they are saved. There is nothing to tick on each one.
Limits in this version
- Policies are stored on this device, per MangoSSH profile, and are not synced through the vault. A teammate's MangoSSH applies only the policies on their own device. The Global settings that live on the vault server are the exception.
- SSH hosts only. Policies do not apply to RDP or VNC hosts.
- Requirement rules warn, they do not refuse. A non-compliant host still connects after the warning.
- Recording and the data-copy blocks run in this app, so they bind honest use of MangoSSH, not a modified client or another tool.
Troubleshooting
| Symptom | Likely cause |
|---|---|
| “0 hosts in scope” | The group or tag does not match exactly, the policy is not Active, or the hosts are not SSH hosts. |
| No host in scope connects | The policy requires JIT approval and this device has no Cloud Vault or Self Hosting Vault. Set one up, or turn the rule off. |
| A host ignores a policy | The policy is in default mode and the host overrides that rule. Its badge reads “Overriding policy …”; click use policy value. |
| Files or forwards refused | “File transfer is blocked for this host by a policy or the host's own settings.” A Block file transfer (SFTP) rule or the host's own switch applies. The same wording with “Port forwarding” comes from the port-forwarding block. |
| MFA or broker warning | A requirement rule covers the host and it falls short. Open the policy's Compliance section and use Fix…. |
| Teammate not recorded | The policy exists only on your device. Create it on theirs too. |