Skip to content

Improve with evidence

Policies

Edit one deployment's constitution, limits, judgment models and evidence retention, each save with a recorded reason.

Policies is the editor for what Integrity holds one deployment to: the constitution its judge reads, the budgets and actuators around it, the models that judge, and what evidence is kept. Every card saves as one object with a recorded reason. Whether decisions are enforced is chosen on the deployment itself.

One policy per deployment#

Choose the project in the top bar; Policies opens the deployment bound to it. A project that backs no deployment on the trajectory engine has no constitution to edit, and the page says so with a way to Deployments. Sections on the left group the cards: Constitution, Judgment models, Evidence, and Request quota. The summary line reads the deployment’s current mode, Observe or Enforce, and links to where it is changed.

Write the constitution#

Each clause is one row: a title and its text. The title is the identifier a judgment cites (clause-2, or a stable name such as supervisor-confirmation), so keep it short and do not reuse it for a different requirement. Write clauses a reviewer can apply to the task’s recorded evidence: what the agent is trying to accomplish, what it must preserve, and which actions need separate authorization.

RequirementRefund-desk example
Task intentResolve the customer’s ticket using the tools you are given.
Protected constraintConfirm the customer approved a refund and its amount before issuing it.
AuthorizationRefunds above $100 need a recorded supervisor confirmation before they are issued.
Evidence neededEscalate unusual requests to a person rather than improvising a resolution.

Auto-numbered clauses can be moved up and down; the order the editor shows is the order the judge reads. A renamed clause keeps its place by its title. Retrieved documents and tool results can supply facts; they cannot replace the constitution.

Limits, actuators and tool constraints#

Limits cap what one request may spend before Integrity holds it: model calls, tokens, wall-clock time, and how many times a divergent step may be corrected. Actuators are what Integrity may do when a step diverges: quarantine the proposal, correct the step under an instruction, narrow the tools the agent may call next, or narrow their arguments. Tool constraints are a JSON Schema per tool; arguments outside the schema hold the request before the tool runs, whatever the judgment says.

All three are part of the constitution. Saving any of them records a new governing revision with the reason you give.

Judgment models#

Judgment models shows the Integrity version this deployment judges with and the monitor and intervention revisions its constitution pins. A version is activated or rolled back as a whole, with a reason and a confirmation; new sessions use the selected version and open sessions keep theirs. New versions are prepared and qualified from Data.

Observe or Enforce is not a policy setting. It is chosen in the Deployments inspector, per deployment, with a reason and a confirmation that names the deployment. In Observe mode every judgment is recorded and nothing is held or corrected; in Enforce mode the actuators apply to real requests.

Evidence and quota#

Evidence sets how many days a session’s evidence stays readable (1 to 365) and how much content is retained: metadata only, redacted content, or full content. Retention applies to sessions opened afterwards; content mode applies from the next read. Content that was not retained cannot be recovered by changing the setting.

The monthly request quota is the one project setting that stays live for a trajectory deployment from this page. It is enforced: requests above it in a UTC calendar month are refused with 429 until the month resets, and an empty quota means no limit.

Where the gateway forwards a deployment’s fleet traffic is deployment configuration, not policy, so it is set in the Deployments inspector under Routing. When the gateway can infer the provider from each request, Automatic is the recommended choice and the manual provider, base URL and credential header sit under Override; otherwise the manual fields are the route and the provider family must match the fleet (OpenAI-compatible for Codex and Cursor, Anthropic for Claude Code). The caller’s own provider credential travels with each request and is never stored.

Revisions and open sessions#

  1. Every save carries a reason. It is recorded in the audit log under Settings with the fields that changed.
  2. A stale draft is refused. If someone else saved first, the page says the saved policy changed and keeps your draft until you load the saved policy.
  3. Open sessions keep their revision. A constitution change governs new sessions at once; a session already open keeps the revision it started under until it is transitioned explicitly.

Trace the effect in Runs#

Each run records the governing revision it was judged under, so behavior before and after a change can be compared without guessing. Keep the old revision and your reason; use graders to compare examples consistently, then return to adaptation if a model update is warranted.