---
title: AuditControlPolicyFlag enum | Wartiva GraphQL API
description: Global audit policy flag as defined in the policy parameter of audit_control(5). Each flag controls a behavioral aspect of the macOS BSM audit subsystem.
url: https://wartiva.com/api-docs/types/audit-control-policy-flag.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `AuditControlPolicyFlag` enum

Global audit policy flag as defined in the policy parameter of audit_control(5). Each flag controls a behavioral aspect of the macOS BSM audit subsystem.

## Values

| Enum Value | Description |
|---|---|
| `AHLT` | Fail-stop: halt the system if auditing cannot continue due to a full audit store. The kernel drains pending records to disk before halting. Mutually exclusive with CNT in practice. Not recommended for most deployments. |
| `ARGE` | Audit environmental variable arguments passed to execve(2). Requires the EX audit class to be active. Produces verbose records; enable only when deep execution tracing is needed. |
| `ARGV` | Audit command-line arguments passed to execve(2). Requires the EX audit class to be active. |
| `CNT` | Continue: allow processes to keep running even when the audit store is exhausted and events cannot be written. Recommended for most deployments to avoid denial-of-service from a full audit log partition. |
| `GROUP` | Include the supplementary groups list in generated audit records. Not implemented on Darwin; supplementary groups are never included on this platform. |
| `PATH` | Include secondary file paths in audit records. Not implemented on Darwin; secondary paths are never included on this platform. |
| `PERZONE` | Enable per-zone auditing. Not implemented on Darwin. |
| `SEQ` | Include a unique sequence number token in each audit record. Not implemented on Darwin. |
| `TRAIL` | Append a trailer token to each audit record. Not implemented on Darwin; trailers are always included. |
| `ZONENAME` | Include a zone ID token with each audit record. Not implemented on Darwin. |

## Used by

- [`AuditPolicyMacOS`](https://wartiva.com/api-docs/types/audit-policy-mac-os.html) type: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.

## Example

### Example

```json
"AHLT"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
