Agent Reference Guide
...
Advance Policy for Application...
Allow Policy
1 min
if the users select allow as the policy action, configured users or users’ groups will be allowed to run the configured application in the selected endpoints in this step the user is expected to choose the endpoints these endpoints could be agents, agent groups (those agent groups are grouped agents under agent dashboard) or device group (from device inventory, if this option is chosen only the agent installed devices will have this policy under that device group) in the last step, users will be configuring child processes when an application is launched it may be required to run some child processes to make the application function since not every application requires this and it could be used as an attack vector, system admins can decide whether this application will be permitted to call and execute child processes or not if this is not configured with care, it can prevent applications from running normally