Core Features

Policy Engine

Define and enforce governance policies for AI agents using declarative YAML configuration.

Overview

The Policy Engine evaluates every action against your defined rules before execution. Policies can ALLOW, BLOCK, WARN, or require APPROVAL for specific actions.

ALLOW

Permit the action

BLOCK

Reject the action

WARN

Allow but flag

APPROVAL

Require human review

Policy Configuration

Define policies using human-readable YAML:

yaml
# policy.yaml
policies:
  - name: block-medical-advice
    description: Prevent AI from giving medical diagnoses
    trigger: output
    action: BLOCK
    conditions:
      - type: contains_pattern
        patterns: ["diagnosis", "prescribe", "medical advice"]
    message: "Medical advice is not permitted"

  - name: require-approval-high-value
    description: Require human approval for transactions over $10,000
    trigger: action
    action: APPROVAL
    conditions:
      - type: action_type
        value: "financial_transaction"
      - type: amount_greater_than
        value: 10000
    approvers: ["finance@company.com"]

  - name: redact-pii-on-output
    trigger: output
    action: REDACT
    entity_types: ["EMAIL", "PHONE", "SSN"]

Checking Policies

Check content before your agent acts on it with POST /api/v1/govern. There is no separate policy-check endpoint and no client.policy namespace in any SDK; the decision comes back in action: allow, redact (use output), deny or block.

javascript
const response = await fetch('https://tork.network/api/v1/govern', {
  method: 'POST',
  headers: {
    Authorization: `Bearer ${process.env.TORK_API_KEY}`,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    content: 'Meeting scheduled for tomorrow',
    agent_id: 'agent-123',
    tool_name: 'send_email',
  }),
});
const result = await response.json();

if (result.action === 'allow' || result.action === 'redact') {
  // Proceed, using the checked text
  await sendEmail(result.output);
} else {
  console.log('Blocked:', result.action, result.receipt_id);
}

From Python, the same endpoint over HTTP with a Bearer token:

python
import os
import requests

response = requests.post(
    "https://tork.network/api/v1/govern",
    headers={"Authorization": f"Bearer {os.environ['TORK_API_KEY']}"},
    json={
        "content": "Meeting scheduled for tomorrow",
        "agent_id": "agent-123",
        "tool_name": "send_email",
    },
    timeout=10,
)
result = response.json()

if result["action"] in ("allow", "redact"):
    # Proceed, using the checked text
    send_email(result["output"])
else:
    print(f"Blocked: {result['action']} ({result['receipt_id']})")

Dynamic Policy Evaluation

Policies can use dynamic conditions based on context:

yaml
policies:
  - name: time-based-restriction
    description: Block certain actions outside business hours
    action: BLOCK
    conditions:
      - type: time_outside
        start: "09:00"
        end: "17:00"
        timezone: "America/New_York"
      - type: action_type
        value: "external_api_call"

  - name: user-role-restriction
    description: Only allow admins to delete resources
    action: BLOCK
    conditions:
      - type: action_type
        value: "delete_resource"
      - type: user_role_not_in
        roles: ["admin", "superadmin"]

Pro Tip: Test policies before deploying to production: create the policy with is_active: false, send representative content to POST /api/v1/govern from a staging API key, and read the receipts before you activate it.

Documentation

Learn to integrate TORK

Upgrade Plan

Current: free

Support

Get help from our team