M11 · OPA / Rego · deterministic control

Policy as code and Q-LOCK

Deny-overrides guardrails that sit between the model's proposal and the real action.

$ python -m fde_toolkit policy --scenario structuring

Workflow

the order an FDE actually runs it in

  1. 1Express each control as a versioned rule with an owner.
  2. 2Evaluate every candidate action against all rules — deny overrides allow.
  3. 3Run the deterministic Q-LOCK gate on structural variables.
  4. 4Return allow, review or reject-isolate with matched rule identifiers.
  5. 5Write the decision to the audit trail whether it allowed or denied.

Function output

deterministic trace

TXN-10021  0 matched rules                        ALLOW  (still audited)
TXN-20051  V1 velocity + V4 ethics linkage breach REJECT_ISOLATE
deterministic gate overrides model confidence 0.93