Overview
Starting October 11, 2026, Cato will update the Guards Policy to simplify rule configuration. The Guards and Agents fields will be combined into a single Source field.
Cato will automatically update existing rules so they continue to apply to the same traffic as before. You don't need to review or edit any rules for these updates to take effect.
What Are the Changes in the Guards Policy?
The Guards Policy will use one Source field instead of separate Guards and Agents fields.
This change affects how you view, create, and edit rules:
- In the rulebase, the Guards and Agents columns will be replaced by the Source column
- In the rule editor, the Guards and Homegrown Agents sections will be replaced by the Source section
- When no source is selected, the rule will default to Any. Previously, a - was shown when no agent or guard was selected
- The rule will use OR logic between Guards and Homegrown Agents in Source. Previously, AND logic was used between values in the Guards and Agents columns
How Will the New Source Field Work?
A rule will apply to traffic from any guard or Homegrown Agent in its Source.
Before this change, a rule including both guards and Homegrown Agents, would apply only to traffic that matched both conditions. For example, traffic must come through a selected guard and from a selected Homegrown Agent.
After this change, the Source field uses OR logic between guards and Homegrown Agents. Each guard or Homegrown Agent in Source widens the rule. The rule applies when traffic comes through any selected guard or from any selected Homegrown Agent.
What Will Happen if Source Is Empty?
An empty Source will mean Any.
Before this change, a rule with no guards and no Homegrown Agents would not apply to any traffic. After this change, a rule with an empty Source applies to all traffic from your guards or Homegrown Agents.
The rules table will show an empty Source as Any.
Will Existing Rules Keep the Same Behavior?
Yes. Existing rules will keep applying to the same traffic as before.
Starting October 11, 2026, Cato will update the Source of any rule that needs a change to keep the same behavior under the new logic. This applies to your published policy and to any unpublished changes in progress.
The updates take effect automatically. You don't need to publish the policy for them to take effect.
Which Rules Will Be Updated or Disabled?
This table explains the logic that is used to migrate the current Guards Policy to the new Source column.
| Current Rule Configuration | Update Result | Reason |
|---|---|---|
| Only guards | No change | The rule will continue to apply to the selected guards |
| Only Homegrown Agents | No change | The rule will continue to apply to the selected Homegrown Agents |
| A Homegrown Agent and its corresponding Guard | No change | The guard and the Homegrown Agent are applied to the same traffic |
| A Guard and the Homegrown Agents mapped to it | Source will be updated to the relevant Homegrown Agents | The Homegrown Agents apply to the same scope of traffic as the original rule. Using the guard would apply to a wider scope of traffic |
| A Guard, the Homegrown Agents mapped to it, and Homegrown Agents on other Guards | Source will be updated to the relevant Homegrown Agents on the guard | Homegrown Agents on other guards have a different traffic scope than the original rule |
| A guard and only Homegrown Agents on other guards | Rule will be disabled | The original rule didn't match traffic due to the AND logic. The updated rule would match traffic due to the OR logic |
| No guards and no Homegrown Agents | Rule will be disabled | The original rule didn't match traffic. The updated rule with an empty Source means Any traffic is matched |
Rules that are already disabled stay disabled. If a disabled rule needs a Source update, Cato still updates it so the rule behaves as expected if you enable it later.
A rule that Cato disables during the update will keep its original Source, so you can review it before re-enabling it.
Unpublished Changes
If you have unpublished changes in the Guards Policy when the update starts, Cato will apply the same updates to them. When you publish those changes, they keep the updated Source values.
Rules that you create or edit after October 11, 2026 use the new logic and aren't changed automatically.
Do I Need to Do Anything?
No action is required. Your policy will keep applying to the same traffic as before.
What Should I Remember When Creating or Editing Rules?
When you create or edit rules, each guard or Homegrown Agent that you add to Source widens the rule.
Use these guidelines:
- Add only the guards and Homegrown Agents that the rule needs to match
- Remember that a rule matches traffic from any source in the list
- Remember that an empty Source means Any