Policy Engine

    Enforce policy before the action runs.

    Turn your policies into rules your agents follow on every run. When an agent is about to break one, AISquare warns, corrects or stops it before the answer or action goes out.

    The problem

    A violation you catch after the fact already happened.

    1
    The Policy Engine works here

    The agent acts

    2

    A report gets written

    3

    Someone finds the damage

    Most tools start at step two. The Policy Engine works before step one.

    Rules from your sources

    From your policy to a rule your agent follows.

    Fund disclosures.pdf

    plus your agent's system prompt

    Draft rulebook · 4 rules

    Every return figure must cite a fund source

    LLM-backed

    Fund disclosures, p.12

    Add the past performance risk warning

    LLM-backed

    Fund disclosures, p.14

    Never share a full account number

    Deterministic

    System prompt

    Mask email and phone in replies

    Deterministic

    System prompt

    AISquare drafts rules from your system prompts, policy documents, PRDs, repos, Google Drive, OneDrive and OPA. Each rule cites its source, and your team decides what goes live. See every source you can connect →

    Deterministic rules hold hard limits like formats and ranges. LLM-backed rules handle judgment calls like advice versus guidance.

    Per-rule modes

    Warn, correct or stop. You choose per rule.

    Warning
    The agent
    Carries on.
    Your customer
    Gets the reply as written.
    Your team
    Sees the run flagged for review.
    Use it for
    New rules you're still tuning.
    Improving
    The agent
    Gets the missing requirement and retries.
    Your customer
    Gets the corrected reply.
    Your team
    Sees the before and after.
    Use it for
    Disclosures, citations and required steps.
    Blocking
    The agent
    Is stopped and told why.
    Your customer
    Gets nothing that breaks the rule.
    Your team
    Gets an alert through webhooks and alerts.
    Use it for
    Lines that must never be crossed.
    LighterStricter

    Audit

    Records only

    Warning

    Improving

    Blocking

    Audit

    Refund above the cap

    Went through. Recorded for review.

    Live

    Refund above the cap

    Held. Your team was alerted.

    One switch, no code change. Rolling out across your agents? See how Audit and Live work with your connectors →

    Evidence

    Every verdict, on the record.

    Each run gets a verdict for every rule it touched.

    Rule
    The exact text that was live, with its source.
    Verdict
    Passed, flagged, corrected or blocked.
    Reasoning
    Why the check passed or failed, in plain language.
    Version
    Which version of the rule was applied.
    Signature
    Signed, so the record can't be changed later.

    Want the reasoning behind a verdict, step by step? See RML and Explainability →

    Verdicts roll up into signed attestations you can map to frameworks like the EU AI Act. See Audit and Attestations →

    Replay

    Change a rule. See what it would have caught.

    Edit a rule and re-grade past runs against it, without running the agent again. Version history shows who changed what.

    v3

    Cite the source for performance figures.

    v4

    Every return figure must cite a fund source and its period.

    Run 398 · would failRun 401 · would failRun 405 · passes

    When the same rule keeps failing, Learnings proposes the fix. See Learnings →

    Why runtime enforcement

    Watching is not controlling.

    ObservabilityInput filtersCloud securityPolicy Engine
    Checks before the action goes out·Input only·✓
    Uses your own policies···✓
    Corrects the agent, not only blocks···✓
    Records every decision with evidenceTraces only··✓

    For developers

    Read every verdict over the API.

    Verdict API

    GET /v1/studios/{studio_id}/runs/{run_id}/policies

    FAQ

    Questions, answered.

    Talk to us

    Does enforcement happen before or after the action?

    Before. Rules are checked before the answer or action goes out; Audit mode only records.

    Where do rules come from?

    Your documents, system prompts, PRDs, repos, Drive, OneDrive, OPA, or written by hand. Each draft rule cites its source and your team approves it.

    What kinds of rules are there?

    Deterministic for hard limits like formats and ranges, LLM-backed for judgment calls like advice versus guidance.

    What do Warning, Improving and Blocking do?

    Warning flags the run, Improving corrects the agent and lets it retry, Blocking holds the action and tells the agent why.

    How does my team hear about escalations?

    Through webhooks and alerts.

    Can I try it without changing behavior?

    Yes. Start in Audit, then switch to Live with no code change.

    Does it work with the agents we already run?

    Yes, through the proxy or the SDK. Explore Connectors.

    How does this help with audits?

    Every verdict is recorded with the rule version and signed, and rolls up into attestations you can map to frameworks like the EU AI Act.

    Stop bad actions before they happen.

    Put your rules in the decision path and enforce them on every run.