Every turn asks permission.
The governance engine sits between the agent and everything it can see, say and do. One policy primitive, synced from your systems, explains every turn — and it is the one boundary the learner cannot cross.
A trustworthy agent is not one that behaves well. It is one that could not misbehave if it tried — because it never held the field, the line or the permission.
See. Say. Do. Why.
Fields and records, not databases.
The agent reads due_amount, never the card number; the DPD bucket, never the credit score. Only accounts in its assigned portfolio, only inside calling hours.
Frozen lines, tone by bucket.
AI disclosure, consent and the grievance line are exact-match. Tone is set by DPD bucket, languages are enumerated, banned phrases are enforced before speech.
Actions carry a tier.
Promise-to-pay, payment link and callback are automatic. A fee waiver waits for a human. Transfers go warm, to a named queue. A deny anywhere beats an allow anywhere.
Every turn has a receipt.
Which policy permitted it, which client system it was synced from, when the grant expires. formant policy --explain answers it for any turn, any call.
A policy is agents × customers × permissions.
There is no separate permissions screen, prompt rule and escalation sheet to keep in step. A policy names a group of agents, a set of customers or journeys, and what those agents may see, say and do for them. Policies nest — tenant, journey, pod — and the lower level only ever narrows the one above.
Deny rules win. A tenant-wide deny on PII cannot be undone by a campaign pod, by a prompt edit, or by a learned improvement.
One turn, explained.
Every turn the engine writes a trace: the fields it read and the policy that allowed each; the fields it was refused and the deny that refused them; the actions it took, and the ones it parked for a human. The trace is what your audit reads.
Illustrative trace. replace with a live --explain
Illustrative call. replace with a live action log
Automatic, approved, or never.
Every action the agent can take carries a tier and a source. The tier decides who acts; the source is the client system or policy the rule was synced from — so your risk team can trace a waiver back to the sheet it came from.
| Action | Tier | Who decides | Where the rule comes from |
|---|---|---|---|
| capture_promise_to_pay | auto | the agent, inside calling hours | journey.collections · LMS field map |
| send_payment_link | auto | the agent, on an opted-in channel only | journey.collections · DPDP consent flag |
| schedule_callback | auto | the agent, within the RBI FPC window | tenant.sync.rbi_fpc_map |
| waive_late_fee | approval | floor supervisor, in the dashboard, mid-call | journey.collections.approvals |
| offer_settlement | approval | credit operations, before the line is spoken | tenant.approvals.credit |
| transfer_to_human | auto · warm | the agent, to the named queue only | pod.sep-campaign-b1.queues |
| disclose_to_third_party | denied | no one — not the agent, not a supervisor | tenant.deny · RBI FPC · deny wins |
Illustrative register for one journey. replace with the client's approval matrix
Your systems stay the source of truth.
Policies are not a document we write once. They are synced continuously from the client's loan management system, do-not-call list and the RBI Fair Practices Code mapping your compliance team owns. When a rule changes upstream, the agent's permission changes with it — no release required.
Grants expire. A campaign pod gets seven days and takes its access with it when it ends.
What the agent may rememberThe learner improves the agent. It cannot touch the policy.
The weekly learning cycle fine-tunes phrasing, objection handling and intent recognition from graded calls. Governance is the one thing it never trains on: a governed line is checked by exact match, not by a model, and a candidate that moves one is blocked by the evaluation gate before a human even sees it.
Illustrative gate. replace with a real candidate diff
