- The agent
- Carries on.
- Your customer
- Gets the reply as written.
- Your team
- Sees the run flagged for review.
- Use it for
- New rules you're still tuning.
Policy Engine
Enforce policy before the action runs.
Turn your policies into rules your agents follow on every run. When an agent is about to break one, AISquare warns, corrects or stops it before the answer or action goes out.
Before
Agent draft“The Global Equity Index Fund has returned an average of 10.5% a year. Past performance does not guarantee future results.”
Missing source and period
After
Sent to customer“The Global Equity Index Fund has returned an average of 10.5% a year over the last 10 years (source: fund factsheet). Past performance does not guarantee future results.”
Source and period added
Policy checks · this reply
4 rules
Every return figure must cite a fund source
Improving · source added before sending
Add the past performance risk warning
Never share a full account number
Mask email and phone in replies
The problem
A violation you catch after the fact already happened.
The agent acts
A report gets written
Someone finds the damage
Most tools start at step two. The Policy Engine works before step one.
Rules from your sources
From your policy to a rule your agent follows.
Fund disclosures.pdf
plus your agent's system prompt
Draft rulebook · 4 rules
Every return figure must cite a fund source
LLM-backedFund disclosures, p.12
Add the past performance risk warning
LLM-backedFund disclosures, p.14
Never share a full account number
DeterministicSystem prompt
Mask email and phone in replies
DeterministicSystem prompt
AISquare drafts rules from your system prompts, policy documents, PRDs, repos, Google Drive, OneDrive and OPA. Each rule cites its source, and your team decides what goes live. See every source you can connect →
Deterministic rules hold hard limits like formats and ranges. LLM-backed rules handle judgment calls like advice versus guidance.
Per-rule modes
Warn, correct or stop. You choose per rule.
- The agent
- Gets the missing requirement and retries.
- Your customer
- Gets the corrected reply.
- Your team
- Sees the before and after.
- Use it for
- Disclosures, citations and required steps.
- The agent
- Is stopped and told why.
- Your customer
- Gets nothing that breaks the rule.
- Your team
- Gets an alert through webhooks and alerts.
- Use it for
- Lines that must never be crossed.
Audit
Records only
Warning
Improving
Blocking
Audit
Refund above the cap
Went through. Recorded for review.
Live
Refund above the cap
Held. Your team was alerted.
One switch, no code change. Rolling out across your agents? See how Audit and Live work with your connectors →
Evidence
Every verdict, on the record.
Each run gets a verdict for every rule it touched.
- Rule
- The exact text that was live, with its source.
- Verdict
- Passed, flagged, corrected or blocked.
- Reasoning
- Why the check passed or failed, in plain language.
- Version
- Which version of the rule was applied.
- Signature
- Signed, so the record can't be changed later.
Want the reasoning behind a verdict, step by step? See RML and Explainability →
Verdicts roll up into signed attestations you can map to frameworks like the EU AI Act. See Audit and Attestations →
Replay
Change a rule. See what it would have caught.
Edit a rule and re-grade past runs against it, without running the agent again. Version history shows who changed what.
Cite the source for performance figures.
Every return figure must cite a fund source and its period.
When the same rule keeps failing, Learnings proposes the fix. See Learnings →
Why runtime enforcement
Watching is not controlling.
| Observability | Input filters | Cloud security | Policy Engine | |
|---|---|---|---|---|
| Checks before the action goes out | · | Input only | · | ✓ |
| Uses your own policies | · | · | · | ✓ |
| Corrects the agent, not only blocks | · | · | · | ✓ |
| Records every decision with evidence | Traces only | · | · | ✓ |
For developers
Read every verdict over the API.
Verdict API
GET /v1/studios/{studio_id}/runs/{run_id}/policiesDoes enforcement happen before or after the action?
Where do rules come from?
What kinds of rules are there?
What do Warning, Improving and Blocking do?
How does my team hear about escalations?
Can I try it without changing behavior?
Does it work with the agents we already run?
How does this help with audits?
Stop bad actions before they happen.
Put your rules in the decision path and enforce them on every run.