Skip to content
Metamynd
Platform Engine

Policy Engine

The deterministic core: composes Standards & SOPs from atoms and returns allow / observe / block / escalate — no LLM in the decision.

Overview

What it does

The Policy Engine is the deterministic core of the platform. Standards and SOPs are composed from atoms — pure boolean predicates — into molecules that return a verdict with a reason code: allow, observe (permitted, but flagged for monitoring), block or escalate, and containment (suspend or quarantine) when a rule requires an agent to be stopped entirely. Across every rule in force the most restrictive verdict wins. There is no LLM in the decision: the same inputs always yield the same verdict, it is re-derivable by anyone, and rules can be edited live in the dashboard with no redeploy. Every reason code is published, and machine-readable at /magp/schema.

Core Functions

Inside Policy Engine

The core functions this engine provides across the Trust Fabric.

Atom → molecule → SOP/Standard
allow / observe / block / escalate
Deterministic & re-derivable
Live edits, no redeploy
One platform

Policy Engine composes with the Trust Fabric

Every engine is independently useful and interoperates through one API-first Trust Fabric — so identity, evidence, policy, risk and certification stay consistent across your AI estate.

Explore more

Related engines

Governance Engine

The authorize gate that runs the policy on every signed action, in cooperative or trustless mode, with human-in-the-loop escalation.

  • The authorize gate (MAGP)
  • Escalation → owner approval
  • Standards compliance check
  • Cooperative & trustless modes
View engine

Action Passport

A signed, single-use proof that one exact action was authorized — bound to that authorization alone, carrying no raw payload content.

  • Issued only on allow / observe
  • Bound 1:1 to a single authorization
  • No amount, merchant or payload data
  • Paired Execution Receipt proves payloadMatch
View engine

Credential Vault

Encrypted-at-rest storage for the upstream credentials your agents need — released just-in-time, only to a gateway, only against a currently-active Action Passport.

  • AES-256-GCM at rest
  • One release path, gated on two factors
  • Tenant derived from the passport, never the caller
  • Every attempt audited, plaintext never logged
View engine

See Policy Engine in action

Book a demo and see how the platform establishes trust across your AI systems.