Emergency lockdown
- Type
- emergency_lockdown
- Category
- Operational
- Enforced atWhen this policy is checked: while someone tries to open, while they create or change an invitation or hold, or after a denial (notify only).
- Access-time
- TiersWhere an admin can set this policy: the whole organization, one integration, or the physical device when the connector supports a device steward.
- Org
- EnforcementHow a configured row behaves. Enforce blocks. Require approval opens an admin inbox when the type supports it. Audit only records and never blocks.
- Enforce
- DefaultWhat happens when no row of this type is configured.
- Not configured — no lockdown.
When active is true, non-admin principals cannot perform inbound cloud opens (and similar writes) on openings that are not classified means_of_egress or fire_door_assembly. Admins remain able to act. Egress and fire-door classes skip this deny so lockdown cannot electrically trap people. This policy never sends PalGate output-disable and never replaces listed exit hardware. Set active to false to lift the lockdown without deleting the row.
When it is enforced
Evaluated when someone opens a door or gate or triggers an entity action. If this policy applies, the open is denied even when roles and grants would otherwise allow it.
Where to set it
Settings → Policies (org).
Policies never grant access. See thepolicies architecture guidefor how org, integration, and device tiers combine.
Arguments
The config object on create/update. Shared row fieldsenforcement (enforce, require_approval,audit_only) and enabled apply to every type;audit_only and disabled rows never block.
| Name | Type | Required | Values | Description |
|---|---|---|---|---|
| active | boolean | No | — | When true, deny non-admin inbound cloud opens on ingress-classified openings. When the field is present it must be a boolean. Default: true (dashboard) |
| output | string or integer | No | — | Optional channel or output id. When set, the policy binds only that output. When omitted, it binds every output of the tier target. A scoped row does not apply when the acting output is unknown. |
How overlapping rows combine
Boolean OR of active across applicable enforcing rows.
Example
Guests, agents, and members cannot open ingress doors from the cloud. An organization admin still can. Means of egress and fire-door openings are not denied by this policy. Listed exit hardware is unchanged.
{ "active": true}Integrations
This type is documented on these connectors:
- Home Assistant (home_assistant)
- KNX (knx)
- MQTT (mqtt)
- PalGate Cloud (palgate_cloud)
- Shelly Cloud (shelly_cloud)
- Shelly Websocket (shelly_websocket)
- Tasmota (tasmota)
- Virtual Access (virtual_access)
- Virtual Demo Devices (virtual_demo)
- Waveshare (waveshare)
Related
- Policy catalog
- Policies architecture guide
- Emergency free egress (emergency_free_egress)
- Quiet hours (quiet_hours)
- Notify on curfew attempt (notify_on_curfew_attempt)
- Rate limit (rate_limit)