+ Try a request
Connecting- 01
Identity
—
- 02
Structural floors
—
- 03
Intent
—
- 04
AI judge
—
- 05
Fusion
—
Pick an example or type your own, then press Decide.
+The rules
Four ways a decision is made
Decision fusion is deliberately simple to reason about. Every verdict maps to exactly one of these.
A floor fires
Instruction overrides, hidden instructions, real secrets and card numbers are strong enough to block on their own.
Two signals agree
When the AI judge and the intent check independently say hostile, the request is blocked.
One signal, no agreement
A judge-only concern is flagged for review instead of blocked — real work isn't stopped by a single guess.
Nothing to see
No floor, no hostile intent, no judge label. Allowed — and still logged with the decision.
+Why not just a model?
A model alone can't be the last word.
An AI judge is good at reading context and bad at being certain. If it could block on its own, every false positive would stop real work — and teams would turn it off.
So the judge is one voice. Structural signals that are never legitimate can block alone. Everything else needs a second, independent signal to agree. When they don't, the request is flagged for a person to look at.
Before any change ships, it runs against a corpus of benign requests that must keep passing — so tightening detection can't quietly break the allow path.
Go deeper in the Simulation Lab →+After the verdict
+Actions wait
High-stakes tool calls can be held for a named approver, then run once with a single-use permit.
+Evidence stays
Each decision is stored with its signals and reason, per agent, for review and export.
+Monitor first
Start with flags only. Turn on enforcement per agent when the decisions look right.
+ The AI watching your AI
Run it on your own traffic.
Monitor mode shows you every verdict and reason before anything is blocked.