Launch Week 3: Five days of launches

Governance Policies

The Governance Policies methods of `client.organization`, in Python and TypeScript.

Overview

The Confident AI SDK exposes every Governance Policy method on the platform. This page documents how to call these methods in all supported languages. See the introduction to install the SDK and set your API key.

Methods

List Governance Policies

Lists your organization's governance policies, newest first. Each comes back with the number of projects enrolled and every control that applies to them, inherited ones included. isBasePolicy tells you whether other policies extend this one, which is what stops it being deleted or extending anything itself. Retrieve a policy by id for each control's definition and verdicts.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.list_governance_policies()

For async mode, call a_list_governance_policies and await it as shown below:

result = await client.organization.a_list_governance_policies(...)

Returns

This method returns an object of type GovernancePolicyList.

Create Governance Policy

Creates a governance policy and returns its id. It starts with no controls attached and no projects enrolled, so use their own endpoints afterwards. A basePolicyIds entry that itself extends another policy is rejected, and that check and the write run in one serializable transaction, so concurrent creates cannot slip past the rule.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.create_governance_policy(
    name="EU AI Act readiness",
    description="The checks every customer-facing agent must pass before release.",
    base_policy_ids=["<GOVERNANCE-POLICY-ID>"],
)

For async mode, call a_create_governance_policy and await it as shown below:

result = await client.organization.a_create_governance_policy(...)

Parameters

ParameterTypeDescription
namestrRequired. The name of the governance policy, unique within your organization.
descriptionOptional[str]What the policy covers. Omit it, or send null, to leave it unset.
base_policy_idsOptional[List[str]]The policies this policy extends, whose controls then also apply to its projects. Omit for a standalone policy. Inheritance is exactly two levels deep, so every id here must name a policy that extends nothing itself.

Returns

This method returns an object of type GovernancePolicyIdentifier.

Get Governance Policy

Retrieves a governance policy in full: every control that applies to its projects with each control's current definition and latest verdict per project, the projects enrolled in it, the policies it extends, the policies that extend it, and the Agent Skill it serves to coding agents. Inherited controls carry a baseGovernancePolicy naming where they come from, since those are attached and detached there rather than here.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.get_governance_policy(
    policy_id="<GOVERNANCE-POLICY-ID>",
)

For async mode, call a_get_governance_policy and await it as shown below:

result = await client.organization.a_get_governance_policy(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.

Returns

This method returns an object of type GovernancePolicy.

Update Governance Policy

Changes a governance policy's name, description, owner, or the policies it extends, and returns the policy in full. Only the fields you send are touched. Inheritance is held to a two-level rule: a policy that other policies extend cannot itself start extending anything, and no id you send may name a policy that already extends another. That check and the write run in one serializable transaction, so a concurrent edit cannot slip a cycle past a guard that was true a moment earlier; the loser of such a collision is rejected and can be retried.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.update_governance_policy(
    policy_id="<GOVERNANCE-POLICY-ID>",
    name="EU AI Act readiness",
    description="The checks every customer-facing agent must pass before release.",
    owner_email="jane@acme.com",
    base_policy_ids=["<GOVERNANCE-POLICY-ID>"],
)

For async mode, call a_update_governance_policy and await it as shown below:

result = await client.organization.a_update_governance_policy(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.
nameOptional[str]The name of the governance policy, unique within your organization.
descriptionOptional[str]What the policy covers. Send null to clear it.
owner_emailOptional[str]The email address of the organization member who should own the policy. They must already be a member of this organization. Send null to leave the policy unowned.
base_policy_idsOptional[List[str]]Replaces the full list of policies this policy extends, so send every id you want kept and an empty array to stop extending anything. Inheritance is exactly two levels deep: a policy that is itself extended cannot start extending, and no id here may name a policy that extends another.

Returns

This method returns an object of type GovernancePolicy.

Delete Governance Policy

Permanently deletes a governance policy and every verdict recorded under it. The projects enrolled in it survive but are left governed by nothing until you enroll them elsewhere, and its controls survive and stay available to other policies. A policy that other policies extend cannot be deleted — detach it from them first. The check and the delete run in one serializable transaction, so a policy cannot be deleted out from under a concurrent write adding a child to it.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.delete_governance_policy(
    policy_id="<GOVERNANCE-POLICY-ID>",
)

For async mode, call a_delete_governance_policy and await it as shown below:

result = await client.organization.a_delete_governance_policy(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.

Returns

This method returns an object of type GovernancePolicyIdentifier.

Assess Governance Policy

Runs every control the policy applies — including inherited ones — against every project enrolled in it, right now, appending a verdict for each control and project pair. Statuses, check counts and streaks all move as a result. Cost and duration scale with controls times projects, and the request does not return until the run finishes, so expect it to be slow on a large policy. The verdicts are not in this response; read them back from the policy or from each project's governance view.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.assess_governance_policy(
    policy_id="<GOVERNANCE-POLICY-ID>",
)

For async mode, call a_assess_governance_policy and await it as shown below:

result = await client.organization.a_assess_governance_policy(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.

Returns

This method returns an object of type GovernancePolicyAssessmentRun.

Assign Projects To Governance Policy

Enrolls projects in a governance policy, so the controls it applies — its own and the ones it inherits — start gating them. A project belongs to at most one policy, so one currently on a different policy is moved here, and one already here is left as it is. Enrolling does not assess — call assess on the policy, or wait for the next scheduled run, for verdicts to appear.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.assign_projects_to_governance_policy(
    policy_id="<GOVERNANCE-POLICY-ID>",
    project_ids=["<PROJECT-ID>"],
)

For async mode, call a_assign_projects_to_governance_policy and await it as shown below:

result = await client.organization.a_assign_projects_to_governance_policy(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.
project_idsList[str]Required. The ids of the projects to assign to, or unassign from, the governance policy. Send at least one. Ids the operation cannot act on are reported back rather than failing the request, so check the response's skipped list.

Returns

This method returns an object of type GovernancePolicyAssignment.

List Governance Policy Projects

Lists the projects enrolled in a governance policy one page at a time, newest first, as ids and names only. Retrieve the policy by id for each project's verdict per control, or a project's own governance view for its verdict history.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.list_governance_policy_projects(
    policy_id="<GOVERNANCE-POLICY-ID>",
    page=1,
    page_size=25,
)

For async mode, call a_list_governance_policy_projects and await it as shown below:

result = await client.organization.a_list_governance_policy_projects(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.
pageOptional[int]The page to return. Defaults to 1.
page_sizeOptional[int]The number of projects per page, at most 100. Defaults to 25.

Returns

This method returns an object of type GovernancePolicyProjectList.

Unassign Projects From Governance Policy

Removes projects from a governance policy, so its controls stop gating them. A project removed this way is left governed by nothing until you enroll it elsewhere, and its recorded verdicts are kept but no longer count towards anything. This is a partial-success operation: an id that is unknown, belongs to another organization, or sits on a different policy is reported in skippedProjectIds rather than failing the request.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.unassign_projects_from_governance_policy(
    policy_id="<GOVERNANCE-POLICY-ID>",
    project_ids=["<PROJECT-ID>"],
)

For async mode, call a_unassign_projects_from_governance_policy and await it as shown below:

result = await client.organization.a_unassign_projects_from_governance_policy(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.
project_idsList[str]Required. The ids of the projects to assign to, or unassign from, the governance policy. Send at least one. Ids the operation cannot act on are reported back rather than failing the request, so check the response's skipped list.

Returns

This method returns an object of type GovernancePolicyUnassignment.

Types

GovernanceControlStatus

The verdict of assessing one governance control against a project or organization.

class GovernanceControlStatus(Enum):
    PASS = "PASS"
    FAIL = "FAIL"
    ERROR = "ERROR"
    NO_DATA = "NO_DATA"

PASS · FAIL · ERROR · NO_DATA

GovernanceControlType

What a governance control checks: RUNTIME watches production behaviour, PRE_DEPLOYMENT_EVALS and PRE_DEPLOYMENT_RED_TEAMING gate a release, and OPERATIONAL covers process rather than the system itself.

class GovernanceControlType(Enum):
    RUNTIME = "RUNTIME"
    PRE_DEPLOYMENT_EVALS = "PRE_DEPLOYMENT_EVALS"
    PRE_DEPLOYMENT_RED_TEAMING = "PRE_DEPLOYMENT_RED_TEAMING"
    OPERATIONAL = "OPERATIONAL"

RUNTIME · PRE_DEPLOYMENT_EVALS · PRE_DEPLOYMENT_RED_TEAMING · OPERATIONAL

GovernanceControlVersionReference

The version of a control's definition an assessment was computed against.

class GovernanceControlVersionReference:
    id: str
    version: str

idstrRequired

The id of the control version, generated by Confident AI.

Example: "<GOVERNANCE-CONTROL-VERSION-ID>"

versionstrRequired

The human-readable label of the control version.

Example: "00.00.02"

GovernancePolicy

A governance policy in full: the controls it applies, the projects enrolled in it, the policies above and below it in the inheritance chain, and the Agent Skill it serves. A policy may extend other policies and inherit their controls, and that chain is exactly two levels deep — a policy that is extended by another cannot extend anything itself.

class GovernancePolicy:
    id: str
    name: str
    description: Optional[str]
    recommended: bool
    projects_count: int = Field(alias="projectsCount")
    controls_count: int = Field(alias="controlsCount")
    documents_count: int = Field(alias="documentsCount")
    created_at: str = Field(alias="createdAt")
    updated_at: str = Field(alias="updatedAt")
    owner: Optional[UserReference]
    skill: Optional[GovernancePolicySkill]
    controls: List[GovernancePolicyControl]
    projects: List[GovernancePolicyProject]
    base_policies: List[GovernancePolicyReference] = Field(alias="basePolicies")
    children_policies: List[GovernancePolicyReference] = Field(alias="childrenPolicies")

idstrRequired

The id of the governance policy, generated by Confident AI.

Example: "<GOVERNANCE-POLICY-ID>"

namestrRequired

The name of the governance policy.

Example: "EU AI Act readiness"

descriptionOptional[str]Required

What the policy covers, or null when it has no description.

Example: "The checks every customer-facing agent must pass before release."

recommendedboolRequired

Whether Confident AI seeded this policy as a recommended starting point rather than your organization authoring it.

Example: false

projects_countintRequired

How many projects are enrolled in this policy.

Example: 4

controls_countintRequired

How many controls apply to this policy, counting the ones inherited from the policies it extends.

Example: 6

documents_countintRequired

How many source documents have been uploaded to this policy, which Confident AI reads when it drafts controls for it.

Example: 2

created_atstrRequired

When the policy was created.

Example: "2025-01-14T09:30:00+00:00"

updated_atstrRequired

When the policy was last changed.

Example: "2025-01-15T11:00:00+00:00"

ownerOptional[UserReference]Required

The organization member who owns the policy, or null when it is unowned.

See UserReference.

skillOptional[GovernancePolicySkill]Required

The Agent Skill served to coding agents working on the projects this policy governs, or null when the policy has none.

See GovernancePolicySkill.

controlsList[GovernancePolicyControl]Required

Every control that applies to this policy's projects, including the ones inherited from the policies it extends, each with its latest verdict per enrolled project.

See GovernancePolicyControl.

projectsList[GovernancePolicyProject]Required

The projects enrolled in this policy, each with its latest verdict per control.

See GovernancePolicyProject.

base_policiesList[GovernancePolicyReference]Required

The policies this policy extends. Their controls apply to this policy's projects but are attached and detached on the base policy, not here.

See GovernancePolicyReference.

children_policiesList[GovernancePolicyReference]Required

The policies that extend this one. While this list is not empty the policy cannot be deleted and cannot itself start extending another policy.

See GovernancePolicyReference.

GovernancePolicyAssessment

One recorded verdict: what one version of one governance control found when it was assessed against one project under this policy. Assessments are append-only, so the current standing of a (control, project) pair is its newest assessment.

class GovernancePolicyAssessment:
    id: str
    governance_control_id: str = Field(alias="governanceControlId")
    governance_control_version: GovernanceControlVersionReference = Field(alias="governanceControlVersion")
    project_id: str = Field(alias="projectId")
    status: GovernanceControlStatus
    evidence: Optional[Dict[str, Any]]
    error: Optional[str]
    created_at: str = Field(alias="createdAt")

idstrRequired

The id of the assessment, generated by Confident AI.

Example: "<GOVERNANCE-ASSESSMENT-ID>"

governance_control_idstrRequired

The id of the governance control that was assessed.

Example: "<GOVERNANCE-CONTROL-ID>"

governance_control_versionGovernanceControlVersionReferenceRequired

project_idstrRequired

The id of the project the control was assessed against.

Example: "<PROJECT-ID>"

statusGovernanceControlStatusRequired

evidenceOptional[Dict[str, Any]]Required

The data behind the verdict. Its keys depend on the control's type, and it is null when the assessment produced none.

Example: {"measured":0.94,"threshold":0.9}

errorOptional[str]Required

Why the check itself failed to run, or null when it ran. This is set on an ERROR verdict and says nothing about whether the project complies.

created_atstrRequired

When the assessment was recorded.

Example: "2025-01-15T02:00:00+00:00"

GovernancePolicyAssessmentRun

What an assessment run covered. The verdicts themselves are read back from the policy or from each project, since a run appends one assessment per (control, project) pair.

class GovernancePolicyAssessmentRun:
    governance_policy: GovernancePolicyReference = Field(alias="governancePolicy")
    projects_assessed: int = Field(alias="projectsAssessed")

governance_policyGovernancePolicyReferenceRequired

projects_assessedintRequired

How many enrolled projects were assessed, which is 0 when the policy has no projects enrolled and nothing was run.

Example: 4

GovernancePolicyAssignment

The outcome of enrolling projects in a governance policy. This is a partial-success operation: every id that names a project in your organization is enrolled, and the rest come back in notFoundProjectIds.

class GovernancePolicyAssignment:
    governance_policy: GovernancePolicyReference = Field(alias="governancePolicy")
    assigned_project_ids: List[str] = Field(alias="assignedProjectIds")
    not_found_project_ids: List[str] = Field(alias="notFoundProjectIds")
    count: int

governance_policyGovernancePolicyReferenceRequired

assigned_project_idsList[str]Required

The ids of the projects now enrolled in this policy, including any that were already enrolled before the call.

Example: ["<PROJECT-ID>"]

not_found_project_idsList[str]Required

The ids that name no project in this organization. They are skipped and reported here rather than failing the whole request.

Example: []

countintRequired

How many projects are now enrolled, the length of assignedProjectIds.

Example: 1

GovernancePolicyControl

A control as one governance policy applies it, resolved to its current definition and its latest verdict per enrolled project. The two base-policy fields record where the control comes from: baseGovernancePolicy is present only on a control the policy inherits, which is attached and detached on that base policy rather than this one, while alsoInBaseGovernancePolicy is present when this policy attaches the control directly and a base policy happens to hold it too. A control with neither field is owned outright by this policy.

class GovernancePolicyControl:
    id: str
    name: str
    description: Optional[str]
    type: GovernanceControlType
    recommended: bool
    configured: bool
    current_version: Optional[GovernanceControlVersionReference] = Field(alias="currentVersion")
    latest_assessments: List[GovernancePolicyAssessment] = Field(alias="latestAssessments")
    base_governance_policy: Optional[GovernancePolicyReference] = Field(default=None, alias="baseGovernancePolicy")
    also_in_base_governance_policy: Optional[GovernancePolicyReference] = Field(default=None, alias="alsoInBaseGovernancePolicy")

idstrRequired

The id of the governance control.

Example: "<GOVERNANCE-CONTROL-ID>"

namestrRequired

The name of the governance control.

Example: "Groundedness above 0.9"

descriptionOptional[str]Required

What the control checks, or null when it has no description.

Example: "Answers must stay grounded in the retrieved context."

typeGovernanceControlTypeRequired

recommendedboolRequired

Whether Confident AI recommends this control for the kind of system the policy governs.

Example: true

configuredboolRequired

Whether the control's current version carries the settings its type needs to run. A control that is not configured is never assessed, so it produces no verdicts.

Example: true

current_versionOptional[GovernanceControlVersionReference]Required

The version of the control's definition an assessment would use now, or null when no version has been snapshotted yet.

See GovernanceControlVersionReference.

latest_assessmentsList[GovernancePolicyAssessment]Required

This control's newest verdict in each project enrolled in the policy. A project with no verdict for the control is absent rather than listed with a null status.

See GovernancePolicyAssessment.

base_governance_policyOptional[GovernancePolicyReference]

also_in_base_governance_policyOptional[GovernancePolicyReference]

GovernancePolicyControlSummary

A control a policy applies, named and typed but not resolved. Retrieve the policy by id, or list its controls, to see each control's configuration state and verdicts.

class GovernancePolicyControlSummary:
    id: str
    name: str
    type: GovernanceControlType

idstrRequired

The id of the governance control.

Example: "<GOVERNANCE-CONTROL-ID>"

namestrRequired

The name of the governance control.

Example: "Groundedness above 0.9"

typeGovernanceControlTypeRequired

GovernancePolicyIdentifier

A governance policy, identified by its id.

class GovernancePolicyIdentifier:
    id: str

idstrRequired

The id of the governance policy.

Example: "<GOVERNANCE-POLICY-ID>"

GovernancePolicyList

Every governance policy in your organization.

class GovernancePolicyList:
    governance_policies: List[GovernancePolicySummary] = Field(alias="governancePolicies")

governance_policiesList[GovernancePolicySummary]Required

Your organization's governance policies, newest created policy first.

See GovernancePolicySummary.

GovernancePolicyProject

A project enrolled in a governance policy, with where it currently stands against each of the policy's controls.

class GovernancePolicyProject:
    id: str
    name: str
    description: Optional[str]
    owner: Optional[UserReference]
    latest_assessments: List[GovernancePolicyAssessment] = Field(alias="latestAssessments")

idstrRequired

The id of the project.

Example: "<PROJECT-ID>"

namestrRequired

The name of the project.

Example: "Customer Support Agent"

descriptionOptional[str]Required

What the project is for, or null when it has no description.

Example: "Front-line support assistant for billing questions."

ownerOptional[UserReference]Required

The organization member who owns the project, or null when nobody holds the owner role on it.

See UserReference.

latest_assessmentsList[GovernancePolicyAssessment]Required

This project's newest verdict for each control the policy applies. A control with no verdict yet is absent rather than listed with a null status.

See GovernancePolicyAssessment.

GovernancePolicyProjectList

One page of the projects enrolled in a governance policy, with the total across all pages.

class GovernancePolicyProjectList:
    projects: List[GovernanceProjectReference]
    total_governance_policy_projects: int = Field(alias="totalGovernancePolicyProjects")
    page: int
    page_size: int = Field(alias="pageSize")

projectsList[GovernanceProjectReference]Required

The projects enrolled in this policy for the current page, newest created project first.

See GovernanceProjectReference.

total_governance_policy_projectsintRequired

How many projects are enrolled in this policy across every page.

Example: 4

pageintRequired

The page this response covers.

Example: 1

page_sizeintRequired

The number of projects per page.

Example: 25

GovernancePolicyReference

A governance policy, named by id.

class GovernancePolicyReference:
    id: str
    name: str

idstrRequired

The id of the governance policy.

Example: "<GOVERNANCE-POLICY-ID>"

namestrRequired

The name of the governance policy.

Example: "EU AI Act readiness"

GovernancePolicySkill

An Agent Skill attached to a governance policy: the instructions Confident AI serves to coding agents working on the projects the policy governs. Confident AI publishes a per-project Agent Skills git repository, and a project enrolled in this policy finds the skill there as skills/governance/SKILL.md, with description in the YAML frontmatter and body as the Markdown beneath it. Nothing about the skill is assessed — it instructs the agent, it is not a control.

class GovernancePolicySkill:
    description: str
    body: str

descriptionstrRequired

One line on what the skill covers, which is how a coding agent decides whether it is relevant to the task in front of it.

Example: "Rules for shipping changes to an AI system governed for EU AI Act readiness."

bodystrRequired

The instructions themselves, in Markdown. This becomes the body of the SKILL.md file, so write it for a coding agent rather than a person and be as explicit as the policy requires.

Example: "## Before opening a pull request\n\n- Run the project's evals and attach the test run link.\n- Never disable a governance control to make a build pass.\n"

GovernancePolicySummary

A governance policy as it appears in a list: what it covers and which controls apply, without resolving each control's definition or verdicts.

class GovernancePolicySummary:
    id: str
    name: str
    description: Optional[str]
    projects_count: int = Field(alias="projectsCount")
    is_base_policy: bool = Field(alias="isBasePolicy")
    controls: List[GovernancePolicyControlSummary]

idstrRequired

The id of the governance policy, generated by Confident AI.

Example: "<GOVERNANCE-POLICY-ID>"

namestrRequired

The name of the governance policy.

Example: "EU AI Act readiness"

descriptionOptional[str]Required

What the policy covers, or null when it has no description.

Example: "The checks every customer-facing agent must pass before release."

projects_countintRequired

How many projects are enrolled in this policy.

Example: 4

is_base_policyboolRequired

Whether other policies extend this one and inherit its controls. While this is true the policy cannot be deleted and cannot itself start extending another policy.

Example: false

controlsList[GovernancePolicyControlSummary]Required

Every control that applies to this policy's projects, including the ones inherited from the policies it extends.

See GovernancePolicyControlSummary.

GovernancePolicyUnassignment

The outcome of removing projects from a governance policy. This is a partial-success operation: only projects currently on this policy are removed, and the rest come back in skippedProjectIds.

class GovernancePolicyUnassignment:
    governance_policy: GovernancePolicyReference = Field(alias="governancePolicy")
    unassigned_project_ids: List[str] = Field(alias="unassignedProjectIds")
    skipped_project_ids: List[str] = Field(alias="skippedProjectIds")
    count: int

governance_policyGovernancePolicyReferenceRequired

unassigned_project_idsList[str]Required

The ids of the projects removed from this policy.

Example: ["<PROJECT-ID>"]

skipped_project_idsList[str]Required

The ids that were not on this policy — unknown, belonging to another organization, or enrolled in a different policy. They are left alone and reported here rather than failing the whole request.

Example: []

countintRequired

How many projects were removed, the length of unassignedProjectIds.

Example: 1

GovernanceProjectReference

A project, named by id.

class GovernanceProjectReference:
    id: str
    name: str

idstrRequired

The id of the project.

Example: "<PROJECT-ID>"

namestrRequired

The name of the project.

Example: "Customer Support Agent"

UserReference

A Confident AI user, as referenced by the records they created.

class UserReference:
    id: str
    email: str
    name: Optional[str]
    image: Optional[str]

idstrRequired

This is the id of the user.

Example: "<USER-ID>"

emailstrRequired

This is the email address of the user.

Example: "jane@acme.com"

nameOptional[str]Required

This is the display name of the user, or null when they have not set one.

Example: "Jane Doe"

imageOptional[str]Required

This is the URL of the user's avatar, or null when they have none.

Building a production pipeline?Design a scalable API workflow for evals, datasets, traces, and promptsTalk to an engineer

Last updated on

Built byConfident AI