# Configure Monitoring Rules
Source: https://docs.chain.link/ace/active-monitoring/guides/configure-monitoring-rules
Last Updated: 2026-10-05

> For the complete documentation index, see [llms.txt](/llms.txt).

A **monitoring rule** maps each TRM risk level to a response (Silently log, Flag, or Enforce) for one monitored token. This guide covers three operations: create the rule, view it, and delete it. For how rules behave, including why one rule can create several decisions, see [Monitoring Rules and Responses](/ace/active-monitoring/concepts/monitoring-rules).

A token has one active rule, and you cannot edit it. To change a rule, delete it and create a new one.

## Prerequisites

- A [monitored token](/ace/active-monitoring/guides/manage-monitored-tokens), with the enforcement functions you want to use.
- For an Enforce response with the balance condition, a primary token ABI that includes `balanceOf(address)`.
- The [onchain role](/ace/active-monitoring/guides/prepare-your-token) granted to your CRE Connect Wallet on every network, so that enforced actions do not revert.
- To use the **API** tab, an ACE API key, sent in the `Authorization: Apikey <API_KEY>` header of each request. See [Create an API key](/ace/getting-started/account-setup#3-create-an-api-key).

## Create a monitoring rule

The following rule is used in both tabs. It applies to a token called Example Treasury Fund, registered as in [Manage Monitored Tokens](/ace/active-monitoring/guides/manage-monitored-tokens): the token has the enforcement function `freezePartialTokens`, and an associated contract called Example Blocklist has `addBlacklist`. The blocklist is only an example of an action on a second contract. If you registered your token alone, keep the freeze and leave out the blocklist action.

TRM gives each address a risk level, from 0 - Unknown to 15 - Severe. See [Watchlist and Screening](/ace/active-monitoring/concepts/screening) for how the level is chosen. The rule chooses a response for each level:

| Risk level                       | Response     | Detail                                                                                                                                                                          |
| -------------------------------- | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 15 - Severe                      | Enforce      | Freeze the balance with `freezePartialTokens(_userAddress, _amount)`, only if the address holds a balance. Add the address to a blocklist with `addBlacklist(account, reason)`. |
| 10 - High                        | Flag         | A person reviews the address.                                                                                                                                                   |
| 5 - Medium, 1 - Low, 0 - Unknown | Silently log | Record only.                                                                                                                                                                    |

## View a monitoring rule

## Delete a monitoring rule

Deleting a rule archives it. Active Monitoring stops creating decisions for the token until you create a new rule. Existing decisions stay in the log.

## Next steps

- [Manage the Watchlist](/ace/active-monitoring/guides/manage-watchlist): add the addresses to screen.
- [Configure the TRM API Key and Screening Schedule](/ace/active-monitoring/guides/configure-screening): start screening.