Skip to content

Usage Policy

  • A usage policy is a contract with your users: what the service is for, what it refuses, and what happens on a violation.
  • Enforce it where every request passes: the gateway, before the request reaches an engine, with a decision that is logged and appealable.
  • Classification is cheap when you reuse what you built: a linear head over the engine’s embeddings, exported as linear-head.schema.json and evaluated as a dot product in Go.
  • Every classifier errs: publish the measured false-positive and false-negative rates on a labelled set, and choose the threshold on purpose.

Read the NIST AI RMF core functions (Govern, Map, Measure, Manage), the OWASP LLM top 10, and two providers’ acceptable-use policies side by side. In the course, ethics.05 writes your policy (formats/policy.v1) and gw.08 enforces it at your gateway with the linear-head classifier (course decision D33).


Policy without enforcement is a wish, and enforcement without policy is arbitrary. The usage policy states categories and actions in a machine-readable file; the gateway evaluates each request against it with a measured classifier; and the ledger records each decision so it can be audited and appealed.

Key ideas:

  • Categories, actions, and appeals: allow, refuse with a reason, or flag for review, per category.
  • Machine-readable: the policy file is a contract (formats/policy.v1) the gateway loads, not prose in a wiki.

Key ideas:

  • Classifier: SequenceClassifier(pool='mean') from L6.5, fitted with IRLS (M07.7) over /v1/embeddings, exported as a linear head.
  • Decision path: the policy middleware sits before routing in the handler chain; refusals and their scores go to the usage ledger with redacted logs.
ModuleTopicKindPass
ethics.05Usage policy at the gatewaypractice10

Its enforcement is the build module gw.08 (usage policy enforcement, Pass 10), whose chapter lives in Gateway.

#ModuleChapterKindPass
1ethics.05Usage policy at the gatewaypractice10
TrackConnection
Responsible AIthe track overview and how the six topics connect
Gatewaythe middleware chain the policy check joins
Agent SDKtool gates as the agent-side counterpart
Securitythe threat model that names abuse cases