<data_dir>/apis/<sandbox>.rules.json and load with it. These commands edit that file, validate every change against the spec, and apply it to a running sandbox at once. See Rules for what a rule can say.
rule list
VERSION is the set version the rule was first saved in. An empty set prints no rules on <sandbox>.
rule add
rules: [...]. Every rule is validated against the spec before anything is written: the route must be declared, an emit event must be declared, an example status must have an example, and ids must be unique. A refusal names the rule and writes nothing.
pikopod up is serving the sandbox, the new set is pushed to it and the last line reads applied to the running sandbox examplepay. A rule the spec cannot honour is refused by name with exit 2:
provenance defaults to manual when the file omits it.
rule drop
rule check
0 when clean, 1 when there is anything to report, 2 when the set cannot load.