Create a policy revision
Path parameters
Request body
How a policy decides whether content/state violates it.
- expression: a PolicyExprEvaluator boolean over turn state.
- llm_judge: a secondary LLM (via model_router) judges against guardrail_text.
Where in a turn a policy's check fires (v2: one point per policy).
agent_response is the single author-facing reply point — the v1 response (per-streamed-unit) + post_response (complete reply) split is an internal runtime detail now, selected by the platform-derived enforcement strategy (buffer-and-gate vs per-unit), not an authored distinction.
What happens when a check fails.
- block: emit a canned safe message, raise PolicyViolationError, short-circuit.
- redact: deterministic regex/truncate (NO LLM rewrite).
- append: append a disclaimer.
- require_approval: route through the HITL approval seam (pre_tool only).
- handoff: hand off via HandoffService (source="policy").
The v1 monitor action is gone — observe-only is the monitor mode now.
The author's INTENT dial — act vs observe. Channel-independent.
- enforce: the policy acts on a violation (block / redact / append / require_approval / handoff) per the platform-derived strategy.
- monitor: shadow/canary — the check runs and records would_be_action but never affects the turn. The safe-rollout default.
The TRANSPORT property v2 conflated into enforcement_mode (buffer-and-gate vs best-effort) is now platform-derived from transport_class at runtime (:func:src.policy.resolution.resolve_strategy), never authored. New-policy default selection is monitor (shadow-first; set at the schema layer).
What to do when a check errors/times out.
Action-derived default (v2): block action → fail_closed; else fail_open.
The streaming latency/guarantee dial (renamed from the v2 severity).
- strict: always enforce before the user sees anything. On a STREAMING transport this holds/buffers (or incrementally gates), accepting brief added latency; on a BLOCKING transport gating is free.
- relaxed: enforce without slowing the conversation — best-effort on streaming transports (content may stream while the check runs), but still a FULL gate on blocking transports (gating is free there). relaxed never means "off".
Configurable only at input·llm_judge and agent_response·expression; forced (and hidden in the UI) elsewhere. New-policy default is relaxed.
Response
Successful Response