Data flow
When a process reads a claim file, the claim’s label follows everything it writes. A rule on that label lets claim data reach only the carrier’s claims system. No allowlist can say that, because the same site is fine for data that never touched a claim.
- Read a claim file
- Write case notes
- Upload refused
$ cat onrails.yamlversion: 1policy: | source AGENT = exec "**" source CLAIM = file "/claims/**" # 198.51.100.20 is the carrier’s claims system. rule claims-to-carrier: block connect endpoint "*" if CLAIM unless target "198.51.100.20" because "Claim data goes only to the carrier’s claims system."