File Transfer Policy
File Transfer Policy controls copies between the MisterShell file catalog and compatible resources. It is part of the Policies page and uses the same ordered rule behavior as Session Policy: enabled rules are evaluated from top to bottom, and the first matching rule decides whether the file is accepted or denied.
The tab contains two views:
- Stores — choose where catalog content attached to a location is kept.
- Rules — allow or deny transfers by resource and path.
Policy authoring and enforcement require the same Enterprise entitlement as Session Policy. Without that entitlement, role permissions still apply to every transfer, existing definitions remain visible, and policy authoring controls show a lock.
Stores
The built-in Root store keeps catalog content locally. You can add a store to a more specific location so new files at that location and below use it. The nearest store up the location tree is selected automatically.
Additional stores can use Amazon S3 or Azure Blob Storage. Select a compatible MisterShell credential and enter the bucket or container settings, then use Test before saving. Existing catalog files stay in the store where they were created; changing a location’s store does not move old content.
Rules
A rule can match any combination of:
- resource locations, types, tags, and user roles;
- transfer direction;
- source path patterns;
- destination path patterns.
Selections within one field are alternatives; populated fields must all match. An empty field matches any value. Path patterns are case-sensitive. Both paths are considered, which lets you allow a catalog source while restricting sensitive destinations on a resource.
Ordinary rules choose Accept or Deny and can optionally record the decision or raise an automation event. Keep specific rules above broader rules. If no enabled rule matches, the transfer is denied. MisterShell therefore keeps at least one rule; a default allow rule is created for a new installation and can be edited to match your policy.
A file selection is fully checked before a transfer task starts. Any denied item refuses that submission instead of silently copying only part of it.
Review policy decisions
Open Review → Policy Logs → File Transfer to inspect decisions recorded by rules with logging enabled. A successful policy decision means the transfer was permitted to start; open its linked session to see whether the actual copy succeeded. Deleted resources and sessions remain visible as retained evidence but are clearly marked and are no longer linked. Decision logs follow the configured policy-log retention period.
Permissions
- View stores, rules, and logs:
app.policy.read. - Create, edit, reorder, test, or reset counters:
app.policy.write. - Delete stores or rules:
app.policy.delete. - Reading compatible credentials is also required when configuring an external store.
Require approval for access
Choose Approve to gate access to a resource before ordinary rules are evaluated. See Access approval rules for consistent Session and File Transfer configuration, grant lifetime, and rule-change behavior.