Policy Assignment and Activation¶
Policy assignment is the controlled handoff between engineering intent and operational enforcement. Policy Profile Composer creates and saves the complete, ordered policy file; Service Management assigns that profile to the L2Proxy service that will enforce it.
End-to-end handoff¶
Access Policies reviewed
↓
Policy Profile assembled and saved
↓
Policy Profile selected in Service Profile
↓
Protected access path confirmed
↓
Service Profile saved
↓
Independent L2Proxy instance started or restarted
↓
Policy active on industrial traffic

Figure — Policy assignment preserves end-to-end handoff from package to enforcement point.
The saved Policy Profile appears in Service Management as managed policy content. It is shown separately from other standalone rule files, helping the operator select the reviewed output of the policy workflow.
Recommended activation review¶
Before activation, confirm:
- The Service Profile has a clear industrial purpose and owner.
- The correct Policy Profile and revision were approved.
- The protected user or industrial path is correct.
- Expected equipment and operations are present in the policy.
- Unexpected or unsafe commands have the intended response.
- Event recording and archive settings match the customer's evidence requirements.
- Normal, denied, and abnormal cases were validated.
- The change and rollback decision were approved.
Activation choices¶
| Action | Industrial use |
|---|---|
| Start | Activate a configured protection service |
| Stop | Remove that service from operation under an approved procedure |
| Restart | Reload a revised operating or Policy Profile for the independent service |
| View log | Confirm startup, diagnose a service issue, or review local operating evidence |
Each action applies to the selected instance, allowing a customer to maintain one access path without interrupting unrelated L2Proxy services.
Policy revision without ambiguity¶
- An Access Policy revision changes one decision.
- A Policy Profile revision changes the complete policy set assigned to a service.
- A Service Profile save changes the operating assignment.
- A service restart activates the approved revision for that instance.
This provides a traceable chain from industrial requirement to active enforcement and supports deliberate rollback to the previously approved combination when required.
Evidence of effective protection¶
After activation, the customer can confirm:
- that the intended service is running;
- which Policy Profile the Service Profile references;
- whether representative permitted operations are accepted;
- whether representative violations are blocked or recorded as approved;
- whether inspection and rule-decision events reach the event archive;
- whether the local service log remains available for troubleshooting.
Next: Multi-Instance Operations.