# Step 2 - Setup Policy

## What is a Policy?

A policy represents a type of data (such as a credit card number) and an action to be performed when data matching that policy is sent to an AI provider. You can find all Policies at `Policy` page.

## How to use Subrosa provided Policies

Subrosa provides a list of common PII and PCI policies. You can customise the action that is taken.

{% hint style="info" %}
All Subrosa Policies are enabled in detect mode by default. You can also disable one or more of the Subrosa Policies.
{% endhint %}

## How to define a Custom Policy

1. Click `Policy` in the side menu
2. Click `Create Policy`
3. Supply the required information and the pattern to match on
4. Select an action to be applied when the pattern matches
5. Click `Confirm`
