Critical-risk tools in Actual
8 of the 64 tools in Actual are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
actual_accounts_deleteDestructiveDelete an account from Actual Budget. Note: The account must not have any transactions. This operation cannot be undone.
-
actual_categories_deleteDestructiveDelete a category from Actual Budget. Transactions using this category will need to be recategorized. This operation cannot be undone.
-
actual_category_groups_deleteDestructiveDelete a category group from Actual Budget. Note: Categories within the group will be moved to a default group or ungrouped. This operation cannot be undone.
-
actual_payees_deleteDestructiveDelete a payee from Actual Budget. Transactions using this payee will have it removed. This operation cannot be undone.
-
actual_rules_deleteDestructiveDelete a budget rule from Actual Budget. The rule will no longer be applied to new or existing transactions. This operation cannot be undone.
-
actual_schedules_deleteDestructivePermanently delete a schedule from Actual Budget. The schedule
-
actual_tags_deleteDestructiveDelete a tag from Actual Budget by its UUID.
-
actual_transactions_deleteDestructiveDelete a transaction from Actual Budget by its ID.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.