Launch Week 3: Five days of launches

Controls

Overview

The Confident AI SDK exposes every Control method on the platform. This page documents how to call these methods in all supported languages. See the introduction to install the SDK and set your API key.

Methods

List Governance Policy Controls

Lists every control the governance policy applies, with each control's current definition and its latest verdict in each enrolled project. Inherited controls are included and carry a baseGovernancePolicy naming where they come from. A control your organization owns but has not attached to this policy does not appear — creating a control does not attach it to anything. This response is not paginated.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.list_governance_policy_controls(
    policy_id="<GOVERNANCE-POLICY-ID>",
)

For async mode, call a_list_governance_policy_controls and await it as shown below:

result = await client.organization.a_list_governance_policy_controls(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.

Returns

This method returns an object of type GovernancePolicyControlList.

Update Governance Policy Controls

Replaces the set of controls the governance policy attaches directly, changing what it gates its projects on from the next assessment onward. This is how a control comes to govern anything: a newly created control is attached to no policy, so it gates nothing until a policy attaches it here. Every id must name a control in your organization, or the whole request is rejected.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.update_governance_policy_controls(
    policy_id="<GOVERNANCE-POLICY-ID>",
    control_ids=["<GOVERNANCE-CONTROL-ID>"],
)

For async mode, call a_update_governance_policy_controls and await it as shown below:

result = await client.organization.a_update_governance_policy_controls(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.
control_idsList[str]Required. The complete set of controls the policy should attach directly. Any control it currently attaches and you leave out is detached, and an empty array detaches all of them. An inherited control cannot appear here — it is attached on the base policy that owns it.

Returns

This method returns an object of type GovernancePolicyControlList.

Remove Governance Policy Controls

Detaches the named controls from the governance policy, leaving its others in place, so the policy stops gating its projects on them. The controls themselves are not deleted and stay available to other policies, and verdicts already recorded are kept. Naming an inherited control is rejected rather than silently ignored.

from confident_ai import ConfidentAI

client = ConfidentAI()

result = client.organization.remove_governance_policy_controls(
    policy_id="<GOVERNANCE-POLICY-ID>",
    control_ids=["<GOVERNANCE-CONTROL-ID>"],
)

For async mode, call a_remove_governance_policy_controls and await it as shown below:

result = await client.organization.a_remove_governance_policy_controls(...)

Parameters

ParameterTypeDescription
policy_idstrRequired. The id of the governance policy.
control_idsList[str]Required. The controls to detach from the policy. Send at least one. An inherited control cannot be detached here — it is managed on the base policy that owns it.

Returns

This method returns an object of type GovernancePolicyControlList.

Types

GovernanceControlStatus

The verdict of assessing one governance control against a project or organization.

class GovernanceControlStatus(Enum):
    PASS = "PASS"
    FAIL = "FAIL"
    ERROR = "ERROR"
    NO_DATA = "NO_DATA"

PASS · FAIL · ERROR · NO_DATA

GovernanceControlType

What a governance control checks: RUNTIME watches production behaviour, PRE_DEPLOYMENT_EVALS and PRE_DEPLOYMENT_RED_TEAMING gate a release, and OPERATIONAL covers process rather than the system itself.

class GovernanceControlType(Enum):
    RUNTIME = "RUNTIME"
    PRE_DEPLOYMENT_EVALS = "PRE_DEPLOYMENT_EVALS"
    PRE_DEPLOYMENT_RED_TEAMING = "PRE_DEPLOYMENT_RED_TEAMING"
    OPERATIONAL = "OPERATIONAL"

RUNTIME · PRE_DEPLOYMENT_EVALS · PRE_DEPLOYMENT_RED_TEAMING · OPERATIONAL

GovernanceControlVersionReference

The version of a control's definition an assessment was computed against.

class GovernanceControlVersionReference:
    id: str
    version: str

idstrRequired

The id of the control version, generated by Confident AI.

Example: "<GOVERNANCE-CONTROL-VERSION-ID>"

versionstrRequired

The human-readable label of the control version.

Example: "00.00.02"

GovernancePolicyAssessment

One recorded verdict: what one version of one governance control found when it was assessed against one project under this policy. Assessments are append-only, so the current standing of a (control, project) pair is its newest assessment.

class GovernancePolicyAssessment:
    id: str
    governance_control_id: str = Field(alias="governanceControlId")
    governance_control_version: GovernanceControlVersionReference = Field(alias="governanceControlVersion")
    project_id: str = Field(alias="projectId")
    status: GovernanceControlStatus
    evidence: Optional[Dict[str, Any]]
    error: Optional[str]
    created_at: str = Field(alias="createdAt")

idstrRequired

The id of the assessment, generated by Confident AI.

Example: "<GOVERNANCE-ASSESSMENT-ID>"

governance_control_idstrRequired

The id of the governance control that was assessed.

Example: "<GOVERNANCE-CONTROL-ID>"

governance_control_versionGovernanceControlVersionReferenceRequired

project_idstrRequired

The id of the project the control was assessed against.

Example: "<PROJECT-ID>"

statusGovernanceControlStatusRequired

evidenceOptional[Dict[str, Any]]Required

The data behind the verdict. Its keys depend on the control's type, and it is null when the assessment produced none.

Example: {"measured":0.94,"threshold":0.9}

errorOptional[str]Required

Why the check itself failed to run, or null when it ran. This is set on an ERROR verdict and says nothing about whether the project complies.

created_atstrRequired

When the assessment was recorded.

Example: "2025-01-15T02:00:00+00:00"

GovernancePolicyControl

A control as one governance policy applies it, resolved to its current definition and its latest verdict per enrolled project. The two base-policy fields record where the control comes from: baseGovernancePolicy is present only on a control the policy inherits, which is attached and detached on that base policy rather than this one, while alsoInBaseGovernancePolicy is present when this policy attaches the control directly and a base policy happens to hold it too. A control with neither field is owned outright by this policy.

class GovernancePolicyControl:
    id: str
    name: str
    description: Optional[str]
    type: GovernanceControlType
    recommended: bool
    configured: bool
    current_version: Optional[GovernanceControlVersionReference] = Field(alias="currentVersion")
    latest_assessments: List[GovernancePolicyAssessment] = Field(alias="latestAssessments")
    base_governance_policy: Optional[GovernancePolicyReference] = Field(default=None, alias="baseGovernancePolicy")
    also_in_base_governance_policy: Optional[GovernancePolicyReference] = Field(default=None, alias="alsoInBaseGovernancePolicy")

idstrRequired

The id of the governance control.

Example: "<GOVERNANCE-CONTROL-ID>"

namestrRequired

The name of the governance control.

Example: "Groundedness above 0.9"

descriptionOptional[str]Required

What the control checks, or null when it has no description.

Example: "Answers must stay grounded in the retrieved context."

typeGovernanceControlTypeRequired

recommendedboolRequired

Whether Confident AI recommends this control for the kind of system the policy governs.

Example: true

configuredboolRequired

Whether the control's current version carries the settings its type needs to run. A control that is not configured is never assessed, so it produces no verdicts.

Example: true

current_versionOptional[GovernanceControlVersionReference]Required

The version of the control's definition an assessment would use now, or null when no version has been snapshotted yet.

See GovernanceControlVersionReference.

latest_assessmentsList[GovernancePolicyAssessment]Required

This control's newest verdict in each project enrolled in the policy. A project with no verdict for the control is absent rather than listed with a null status.

See GovernancePolicyAssessment.

base_governance_policyOptional[GovernancePolicyReference]

also_in_base_governance_policyOptional[GovernancePolicyReference]

GovernancePolicyControlList

The controls a governance policy applies, as they stand after the call.

class GovernancePolicyControlList:
    controls: List[GovernancePolicyControl]
    total_governance_policy_controls: int = Field(alias="totalGovernancePolicyControls")

controlsList[GovernancePolicyControl]Required

Every control that applies to this policy's projects, including the ones inherited from the policies it extends.

See GovernancePolicyControl.

total_governance_policy_controlsintRequired

How many controls apply to this policy, the length of controls. This response is not paginated.

Example: 6

GovernancePolicyReference

A governance policy, named by id.

class GovernancePolicyReference:
    id: str
    name: str

idstrRequired

The id of the governance policy.

Example: "<GOVERNANCE-POLICY-ID>"

namestrRequired

The name of the governance policy.

Example: "EU AI Act readiness"

Building a production pipeline?Design a scalable API workflow for evals, datasets, traces, and promptsTalk to an engineer

Last updated on

Built byConfident AI