M11 · OPA / Rego · deterministic control
Policy as code and Q-LOCK
Deny-overrides guardrails that sit between the model's proposal and the real action.
$ python -m fde_toolkit policy --scenario structuring
Workflow
the order an FDE actually runs it in
- 1Express each control as a versioned rule with an owner.
- 2Evaluate every candidate action against all rules — deny overrides allow.
- 3Run the deterministic Q-LOCK gate on structural variables.
- 4Return allow, review or reject-isolate with matched rule identifiers.
- 5Write the decision to the audit trail whether it allowed or denied.
Function output
deterministic trace
TXN-10021 0 matched rules ALLOW (still audited) TXN-20051 V1 velocity + V4 ethics linkage breach REJECT_ISOLATE deterministic gate overrides model confidence 0.93
