Controls
Overview
The Confident AI SDK exposes every Control method on the platform. This page documents how to call these methods in all supported languages. See the introduction to install the SDK and set your API key.
Methods
List Governance Policy Controls
Lists every control the governance policy applies, with each control's current definition and its latest verdict in each enrolled project. Inherited controls are included and carry a baseGovernancePolicy naming where they come from. A control your organization owns but has not attached to this policy does not appear — creating a control does not attach it to anything. This response is not paginated.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.list_governance_policy_controls(
policy_id="<GOVERNANCE-POLICY-ID>",
)For async mode, call a_list_governance_policy_controls and await it as shown below:
result = await client.organization.a_list_governance_policy_controls(...)Parameters
| Parameter | Type | Description |
|---|---|---|
policy_id | str | Required. The id of the governance policy. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.listGovernancePolicyControls(
"<GOVERNANCE-POLICY-ID>",
);Parameters
| Parameter | Type | Description |
|---|---|---|
policyId | string | Required. The id of the governance policy. |
Returns
This method returns an object of type GovernancePolicyControlList.
Update Governance Policy Controls
Replaces the set of controls the governance policy attaches directly, changing what it gates its projects on from the next assessment onward. This is how a control comes to govern anything: a newly created control is attached to no policy, so it gates nothing until a policy attaches it here. Every id must name a control in your organization, or the whole request is rejected.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.update_governance_policy_controls(
policy_id="<GOVERNANCE-POLICY-ID>",
control_ids=["<GOVERNANCE-CONTROL-ID>"],
)For async mode, call a_update_governance_policy_controls and await it as shown below:
result = await client.organization.a_update_governance_policy_controls(...)Parameters
| Parameter | Type | Description |
|---|---|---|
policy_id | str | Required. The id of the governance policy. |
control_ids | List[str] | Required. The complete set of controls the policy should attach directly. Any control it currently attaches and you leave out is detached, and an empty array detaches all of them. An inherited control cannot appear here — it is attached on the base policy that owns it. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.updateGovernancePolicyControls(
"<GOVERNANCE-POLICY-ID>",
["<GOVERNANCE-CONTROL-ID>"],
);Parameters
| Parameter | Type | Description |
|---|---|---|
policyId | string | Required. The id of the governance policy. |
controlIds | string[] | Required. The complete set of controls the policy should attach directly. Any control it currently attaches and you leave out is detached, and an empty array detaches all of them. An inherited control cannot appear here — it is attached on the base policy that owns it. |
Returns
This method returns an object of type GovernancePolicyControlList.
Remove Governance Policy Controls
Detaches the named controls from the governance policy, leaving its others in place, so the policy stops gating its projects on them. The controls themselves are not deleted and stay available to other policies, and verdicts already recorded are kept. Naming an inherited control is rejected rather than silently ignored.
from confident_ai import ConfidentAI
client = ConfidentAI()
result = client.organization.remove_governance_policy_controls(
policy_id="<GOVERNANCE-POLICY-ID>",
control_ids=["<GOVERNANCE-CONTROL-ID>"],
)For async mode, call a_remove_governance_policy_controls and await it as shown below:
result = await client.organization.a_remove_governance_policy_controls(...)Parameters
| Parameter | Type | Description |
|---|---|---|
policy_id | str | Required. The id of the governance policy. |
control_ids | List[str] | Required. The controls to detach from the policy. Send at least one. An inherited control cannot be detached here — it is managed on the base policy that owns it. |
import { ConfidentAI } from "confident-ai";
const client = new ConfidentAI();
const result = await client.organization.removeGovernancePolicyControls(
"<GOVERNANCE-POLICY-ID>",
["<GOVERNANCE-CONTROL-ID>"],
);Parameters
| Parameter | Type | Description |
|---|---|---|
policyId | string | Required. The id of the governance policy. |
controlIds | string[] | Required. The controls to detach from the policy. Send at least one. An inherited control cannot be detached here — it is managed on the base policy that owns it. |
Returns
This method returns an object of type GovernancePolicyControlList.
Types
GovernanceControlStatus
The verdict of assessing one governance control against a project or organization.
class GovernanceControlStatus(Enum):
PASS = "PASS"
FAIL = "FAIL"
ERROR = "ERROR"
NO_DATA = "NO_DATA"enum GovernanceControlStatus {
PASS = "PASS",
FAIL = "FAIL",
ERROR = "ERROR",
NO_DATA = "NO_DATA",
}PASS · FAIL · ERROR · NO_DATA
GovernanceControlType
What a governance control checks: RUNTIME watches production behaviour, PRE_DEPLOYMENT_EVALS and PRE_DEPLOYMENT_RED_TEAMING gate a release, and OPERATIONAL covers process rather than the system itself.
class GovernanceControlType(Enum):
RUNTIME = "RUNTIME"
PRE_DEPLOYMENT_EVALS = "PRE_DEPLOYMENT_EVALS"
PRE_DEPLOYMENT_RED_TEAMING = "PRE_DEPLOYMENT_RED_TEAMING"
OPERATIONAL = "OPERATIONAL"enum GovernanceControlType {
RUNTIME = "RUNTIME",
PRE_DEPLOYMENT_EVALS = "PRE_DEPLOYMENT_EVALS",
PRE_DEPLOYMENT_RED_TEAMING = "PRE_DEPLOYMENT_RED_TEAMING",
OPERATIONAL = "OPERATIONAL",
}RUNTIME · PRE_DEPLOYMENT_EVALS · PRE_DEPLOYMENT_RED_TEAMING · OPERATIONAL
GovernanceControlVersionReference
The version of a control's definition an assessment was computed against.
class GovernanceControlVersionReference:
id: str
version: stridstrRequired
The id of the control version, generated by Confident AI.
Example: "<GOVERNANCE-CONTROL-VERSION-ID>"
versionstrRequired
The human-readable label of the control version.
Example: "00.00.02"
interface GovernanceControlVersionReference {
id: string;
version: string;
}idstringRequired
The id of the control version, generated by Confident AI.
Example: "<GOVERNANCE-CONTROL-VERSION-ID>"
versionstringRequired
The human-readable label of the control version.
Example: "00.00.02"
GovernancePolicyAssessment
One recorded verdict: what one version of one governance control found when it was assessed against one project under this policy. Assessments are append-only, so the current standing of a (control, project) pair is its newest assessment.
class GovernancePolicyAssessment:
id: str
governance_control_id: str = Field(alias="governanceControlId")
governance_control_version: GovernanceControlVersionReference = Field(alias="governanceControlVersion")
project_id: str = Field(alias="projectId")
status: GovernanceControlStatus
evidence: Optional[Dict[str, Any]]
error: Optional[str]
created_at: str = Field(alias="createdAt")idstrRequired
The id of the assessment, generated by Confident AI.
Example: "<GOVERNANCE-ASSESSMENT-ID>"
governance_control_idstrRequired
The id of the governance control that was assessed.
Example: "<GOVERNANCE-CONTROL-ID>"
governance_control_versionGovernanceControlVersionReferenceRequired
project_idstrRequired
The id of the project the control was assessed against.
Example: "<PROJECT-ID>"
statusGovernanceControlStatusRequired
evidenceOptional[Dict[str, Any]]Required
The data behind the verdict. Its keys depend on the control's type, and it is null when the assessment produced none.
Example: {"measured":0.94,"threshold":0.9}
errorOptional[str]Required
Why the check itself failed to run, or null when it ran. This is set on an ERROR verdict and says nothing about whether the project complies.
created_atstrRequired
When the assessment was recorded.
Example: "2025-01-15T02:00:00+00:00"
interface GovernancePolicyAssessment {
id: string;
governanceControlId: string;
governanceControlVersion: GovernanceControlVersionReference;
projectId: string;
status: GovernanceControlStatus;
evidence: Record<string, unknown> | null;
error: string | null;
createdAt: string;
}idstringRequired
The id of the assessment, generated by Confident AI.
Example: "<GOVERNANCE-ASSESSMENT-ID>"
governanceControlIdstringRequired
The id of the governance control that was assessed.
Example: "<GOVERNANCE-CONTROL-ID>"
governanceControlVersionGovernanceControlVersionReferenceRequired
projectIdstringRequired
The id of the project the control was assessed against.
Example: "<PROJECT-ID>"
statusGovernanceControlStatusRequired
evidenceRecord<string, unknown> | nullRequired
The data behind the verdict. Its keys depend on the control's type, and it is null when the assessment produced none.
Example: {"measured":0.94,"threshold":0.9}
errorstring | nullRequired
Why the check itself failed to run, or null when it ran. This is set on an ERROR verdict and says nothing about whether the project complies.
createdAtstringRequired
When the assessment was recorded.
Example: "2025-01-15T02:00:00+00:00"
GovernancePolicyControl
A control as one governance policy applies it, resolved to its current definition and its latest verdict per enrolled project. The two base-policy fields record where the control comes from: baseGovernancePolicy is present only on a control the policy inherits, which is attached and detached on that base policy rather than this one, while alsoInBaseGovernancePolicy is present when this policy attaches the control directly and a base policy happens to hold it too. A control with neither field is owned outright by this policy.
class GovernancePolicyControl:
id: str
name: str
description: Optional[str]
type: GovernanceControlType
recommended: bool
configured: bool
current_version: Optional[GovernanceControlVersionReference] = Field(alias="currentVersion")
latest_assessments: List[GovernancePolicyAssessment] = Field(alias="latestAssessments")
base_governance_policy: Optional[GovernancePolicyReference] = Field(default=None, alias="baseGovernancePolicy")
also_in_base_governance_policy: Optional[GovernancePolicyReference] = Field(default=None, alias="alsoInBaseGovernancePolicy")idstrRequired
The id of the governance control.
Example: "<GOVERNANCE-CONTROL-ID>"
namestrRequired
The name of the governance control.
Example: "Groundedness above 0.9"
descriptionOptional[str]Required
What the control checks, or null when it has no description.
Example: "Answers must stay grounded in the retrieved context."
typeGovernanceControlTypeRequired
recommendedboolRequired
Whether Confident AI recommends this control for the kind of system the policy governs.
Example: true
configuredboolRequired
Whether the control's current version carries the settings its type needs to run. A control that is not configured is never assessed, so it produces no verdicts.
Example: true
current_versionOptional[GovernanceControlVersionReference]Required
The version of the control's definition an assessment would use now, or null when no version has been snapshotted yet.
latest_assessmentsList[GovernancePolicyAssessment]Required
This control's newest verdict in each project enrolled in the policy. A project with no verdict for the control is absent rather than listed with a null status.
base_governance_policyOptional[GovernancePolicyReference]
also_in_base_governance_policyOptional[GovernancePolicyReference]
interface GovernancePolicyControl {
id: string;
name: string;
description: string | null;
type: GovernanceControlType;
recommended: boolean;
configured: boolean;
currentVersion: GovernanceControlVersionReference | null;
latestAssessments: GovernancePolicyAssessment[];
baseGovernancePolicy?: GovernancePolicyReference;
alsoInBaseGovernancePolicy?: GovernancePolicyReference;
}idstringRequired
The id of the governance control.
Example: "<GOVERNANCE-CONTROL-ID>"
namestringRequired
The name of the governance control.
Example: "Groundedness above 0.9"
descriptionstring | nullRequired
What the control checks, or null when it has no description.
Example: "Answers must stay grounded in the retrieved context."
typeGovernanceControlTypeRequired
recommendedbooleanRequired
Whether Confident AI recommends this control for the kind of system the policy governs.
Example: true
configuredbooleanRequired
Whether the control's current version carries the settings its type needs to run. A control that is not configured is never assessed, so it produces no verdicts.
Example: true
currentVersionGovernanceControlVersionReference | nullRequired
The version of the control's definition an assessment would use now, or null when no version has been snapshotted yet.
latestAssessmentsGovernancePolicyAssessment[]Required
This control's newest verdict in each project enrolled in the policy. A project with no verdict for the control is absent rather than listed with a null status.
baseGovernancePolicyGovernancePolicyReference
alsoInBaseGovernancePolicyGovernancePolicyReference
GovernancePolicyControlList
The controls a governance policy applies, as they stand after the call.
class GovernancePolicyControlList:
controls: List[GovernancePolicyControl]
total_governance_policy_controls: int = Field(alias="totalGovernancePolicyControls")controlsList[GovernancePolicyControl]Required
Every control that applies to this policy's projects, including the ones inherited from the policies it extends.
total_governance_policy_controlsintRequired
How many controls apply to this policy, the length of controls. This response is not paginated.
Example: 6
interface GovernancePolicyControlList {
controls: GovernancePolicyControl[];
totalGovernancePolicyControls: number;
}controlsGovernancePolicyControl[]Required
Every control that applies to this policy's projects, including the ones inherited from the policies it extends.
totalGovernancePolicyControlsnumberRequired
How many controls apply to this policy, the length of controls. This response is not paginated.
Example: 6
GovernancePolicyReference
A governance policy, named by id.
class GovernancePolicyReference:
id: str
name: stridstrRequired
The id of the governance policy.
Example: "<GOVERNANCE-POLICY-ID>"
namestrRequired
The name of the governance policy.
Example: "EU AI Act readiness"
interface GovernancePolicyReference {
id: string;
name: string;
}idstringRequired
The id of the governance policy.
Example: "<GOVERNANCE-POLICY-ID>"
namestringRequired
The name of the governance policy.
Example: "EU AI Act readiness"
Last updated on