v1

latestOpenAPI 3.1.0raw.githubusercontent.com2026-06-304917042.1 MB
policies

Create a policy

post/v1/policies

Request body

namestring required
descriptionstring nullable
enabledboolean
scope'organization' | 'attachable'

Who the policy applies to.

organization policies auto-apply to every assistant in the org (NOT listed in an assistant's policy_refs). attachable policies apply only where an assistant revision opts in via policy_refs.

metadataobject nullable
check_type'expression' | 'llm_judge' required

How a policy decides whether content/state violates it.

  • expression: a PolicyExprEvaluator boolean over turn state.
  • llm_judge: a secondary LLM (via model_router) judges against guardrail_text.
check_configobject
enforcement_point'input' | 'pre_tool' | 'post_tool' | 'agent_response' required

Where in a turn a policy's check fires (v2: one point per policy).

agent_response is the single author-facing reply point — the v1 response (per-streamed-unit) + post_response (complete reply) split is an internal runtime detail now, selected by the platform-derived enforcement strategy (buffer-and-gate vs per-unit), not an authored distinction.

action'block' | 'redact' | 'append' | 'require_approval' | 'handoff' required

What happens when a check fails.

  • block: emit a canned safe message, raise PolicyViolationError, short-circuit.
  • redact: deterministic regex/truncate (NO LLM rewrite).
  • append: append a disclaimer.
  • require_approval: route through the HITL approval seam (pre_tool only).
  • handoff: hand off via HandoffService (source="policy").

The v1 monitor action is gone — observe-only is the monitor mode now.

action_configobject nullable
tool_targetstring nullable
mode'enforce' | 'monitor'

The author's INTENT dial — act vs observe. Channel-independent.

  • enforce: the policy acts on a violation (block / redact / append / require_approval / handoff) per the platform-derived strategy.
  • monitor: shadow/canary — the check runs and records would_be_action but never affects the turn. The safe-rollout default.

The TRANSPORT property v2 conflated into enforcement_mode (buffer-and-gate vs best-effort) is now platform-derived from transport_class at runtime (:func:src.policy.resolution.resolve_strategy), never authored. New-policy default selection is monitor (shadow-first; set at the schema layer).

on_error'fail_open' | 'fail_closed'

What to do when a check errors/times out.

Action-derived default (v2): block action → fail_closed; else fail_open.

timeout_msinteger nullable
strictness'strict' | 'relaxed'

The streaming latency/guarantee dial (renamed from the v2 severity).

  • strict: always enforce before the user sees anything. On a STREAMING transport this holds/buffers (or incrementally gates), accepting brief added latency; on a BLOCKING transport gating is free.
  • relaxed: enforce without slowing the conversation — best-effort on streaming transports (content may stream while the check runs), but still a FULL gate on blocking transports (gating is free there). relaxed never means "off".

Configurable only at input·llm_judge and agent_response·expression; forced (and hidden in the UI) elsewhere. New-policy default is relaxed.

priorityinteger

Response

Successful Response

idstring uuid required
organization_idstring uuid required
namestring required
descriptionstring nullable
enabledboolean required
scopestring required
active_revision_idstring uuid nullable
metadataobject
created_atstring date-time required
updated_atstring date-time required