Skip to main content
Each change to a policy saves a numbered version. Old versions are never edited. Any version can be viewed, compared, or restored.

What a version captures

A version is a snapshot of what the policy enforces: its name, description, type, scope, priority, active state, and full rule set. Assignments (which agents, wallets, or cards a policy applies to) are tracked separately and are not part of a version. Conto appends a new version whenever you:
  • Create a policy (version 1).
  • Change its metadata (name, description, priority, scope, or active state).
  • Add, edit, replace, or remove any rule.
  • Roll back to an earlier version (the rollback itself is recorded as a new version).
Versions are numbered per policy, starting at 1 and increasing by one.

List the history

Returns versions newest first, each with its changeType, who made the change, when, and a rule count. Use limit and offset to page.

Read one version

Returns the full snapshot for that version, including every rule.

Compare two versions

The diff reports metadata fields that changed and the rules that were added or removed. Rules are compared by content, so a rule that only changed position is not reported, and an edited rule shows up as one removed plus one added.

Roll back

Rollback restores the policy’s definition and rules from the target version and appends a new ROLLED_BACK version. The policy type is fixed for the life of a policy and is never changed by a rollback.
Rollback is a change to a live control, so it runs through the same governance approval workflow as any other policy edit when your organization requires it. See Require a second approver for changes. If the target version is organization-scoped but the policy currently has assignments, rollback is refused until you remove the assignments, because organization policies apply automatically and cannot be assigned.

Audit trail

Version history is for reviewing and restoring policy state. It is separate from the tamper-evident audit log, which independently records every policy change in a per-organization hash chain. See the audit integrity section on the security page.