Policy engine

Guardrails as code

Policies compile to the runtime gateway and evaluate inline on every prompt, tool call and completion. Turning a policy off is itself a logged, attributable governance event.

Policies published

23

5 knowledge base policies

Currently enforcing

21

2 disabled

Evaluations / 30d

2.61M

mean added latency 54 ms p99

Policy triggers / 30d

31,110

blocks, masks and escalations

POL-001 · All egress

No customer PII outside India

criticalOwner · CISO148 triggers / 30d

When

  • payload matches PAN / Aadhaar / account recognisers
  • destination region ≠ ap-south-1

Then

  • block request
  • raise critical finding
  • notify DPO
Enforcing inline at the gatewayInspect rule →

POL-002 · Servicing agents

No account closure without approval

criticalOwner · Head of Operations62 triggers / 30d

When

  • tool = accounts.close
  • actor is agent

Then

  • park for human approval
  • log to ledger
Enforcing inline at the gatewayInspect rule →
highOwner · Model Risk37 triggers / 30d

When

  • decision = decline
  • reason codes missing

Then

  • block response
  • return adverse-action template
Enforcing inline at the gatewayInspect rule →
criticalOwner · CISO91 triggers / 30d

When

  • endpoint not in sanctioned registry

Then

  • block
  • revoke session token
Enforcing inline at the gatewayInspect rule →
criticalOwner · Payments Risk214 triggers / 30d

When

  • amount > ₹10,00,000
  • initiated by agent

Then

  • escalate to approver
  • SLA 30 min
Enforcing inline at the gatewayInspect rule →

POL-006 · All prompts & logs

PII masking required

highOwner · DPO1,830 triggers / 30d

When

  • recogniser hit on stored payload

Then

  • mask in transit
  • mask in ledger
Enforcing inline at the gatewayInspect rule →

POL-007 · All channels

Sensitive prompts blocked

highOwner · AppSec76 triggers / 30d

When

  • prompt classified restricted-topic

Then

  • block
  • coach user
Enforcing inline at the gatewayInspect rule →

POL-008 · Retrieval + tools

Prompt injection protection

criticalOwner · AppSec268 triggers / 30d

When

  • injection classifier score > 0.72

Then

  • strip untrusted segment
  • block on repeat
Enforcing inline at the gatewayInspect rule →

POL-009 · Customer-facing

Toxicity detection

mediumOwner · Customer Experience44 triggers / 30d

When

  • toxicity > 0.4 on output

Then

  • rewrite
  • warn agent
Enforcing inline at the gatewayInspect rule →

POL-010 · All channels

Jailbreak detection

highOwner · Red Team59 triggers / 30d

When

  • known jailbreak signature
  • role-play override attempt

Then

  • block
  • open security case
Enforcing inline at the gatewayInspect rule →

POL-011 · AML agents

Narrative grounding required

mediumOwner · Financial Crime33 triggers / 30d

When

  • citation coverage < 80%

Then

  • warn
  • attach source list
Enforcing inline at the gatewayInspect rule →

POL-012 · Wealth copilots

Suitability disclosure on advice

mediumOwner · Wealth Compliance12 triggers / 30d

When

  • output contains product recommendation

Then

  • append disclosure
  • log consent
Disabled — evaluations logged onlyInspect rule →

POL-013 · Screening agents

Sanctions match cannot auto-clear

criticalOwner · Financial Crime88 triggers / 30d

When

  • match probability > 0.75

Then

  • park for sanctions desk
  • freeze payment
Enforcing inline at the gatewayInspect rule →

POL-014 · All model calls

Restricted payloads stay in-region

criticalOwner · Platform412 triggers / 30d

When

  • data class = Restricted
  • endpoint region ≠ India

Then

  • reroute to in-VPC model
  • log deviation
Enforcing inline at the gatewayInspect rule →

POL-015 · Vendor endpoints

Model version pinning required

mediumOwner · Model Risk21 triggers / 30d

When

  • provider version differs from approved pin

Then

  • hold traffic
  • notify model owner
Enforcing inline at the gatewayInspect rule →

POL-016 · Marketing & advisory

Consent withdrawal must suppress outreach

highOwner · DPO1,904 triggers / 30d

When

  • customer consent = withdrawn
  • output contains recommendation

Then

  • suppress output
  • record suppression
Enforcing inline at the gatewayInspect rule →

POL-017 · All agents

Max agent turns per session

lowOwner · Platform305 triggers / 30d

When

  • turns in session > 12

Then

  • terminate loop
  • raise cost anomaly
Enforcing inline at the gatewayInspect rule →
highOwner · Internal Audit25,148 triggers / 30d

When

  • decision record written

Then

  • append hash chain
  • RFC-3161 timestamp
Enforcing inline at the gatewayInspect rule →

KBP-001 · Knowledge base · retail-credit

Retail credit knowledge base must cite approved policy manual

highknowledge baseOwner · Model Risk214 triggers / 30d

When

  • retrieval collection = kb/retail-credit
  • citation coverage < 90%

Then

  • block response
  • return the approved manual excerpt
  • notify knowledge owner
Enforcing inline at the gatewayInspect rule →

KBP-002 · Knowledge base · all collections

No customer documents in the general knowledge base

criticalknowledge baseOwner · DPO76 triggers / 30d

When

  • ingested document contains PAN / Aadhaar / account number
  • collection ≠ kb/case-files

Then

  • quarantine document
  • raise critical finding
  • notify DPO
Enforcing inline at the gatewayInspect rule →

KBP-003 · Knowledge base · regulatory

Stale regulatory circulars cannot ground answers

highknowledge baseOwner · Compliance41 triggers / 30d

When

  • source document age > 180 days
  • document type = circular

Then

  • exclude from retrieval
  • flag for knowledge refresh
  • warn requester
Enforcing inline at the gatewayInspect rule →
mediumknowledge baseOwner · Wealth Compliance18 triggers / 30d

When

  • collection = kb/wealth-products
  • requester lacks adviser entitlement

Then

  • deny retrieval
  • log entitlement gap
Enforcing inline at the gatewayInspect rule →

KBP-005 · Knowledge base · ingestion

Knowledge base ingestion requires owner approval

mediumknowledge baseOwner · Platform9 triggers / 30d

When

  • new source registered
  • approval record absent

Then

  • park ingestion for approval
  • write ledger entry
Disabled — evaluations logged onlyInspect rule →