LSAS Platform

Govern what AI can say, do, and decide — at runtime.

Policy packs in LSAS Platform

Policy packs select validators and map weighted findings into decisions. Their names describe intended technical controls; they do not establish legal compliance or clinical safety.

Exact assignments

The gateway selects an application assignment first, then the default for the same tenant and environment. The selected pack ID and version must resolve exactly. Duplicate, missing, unknown, or unavailable production authority fails before a provider call. Decision events record the selected ID and version; historical missing fields are not fabricated.

The console exposes the bundled catalog and role-protected assignment changes. Threshold changes require reviewed versioned pack definitions. Request headers and sandbox controls do not edit production assignments or publish a new policy.

Findings, obligations, and receipts

Validators inspect supported normalized content and emit rule findings. The pack supplies weights and warn/redact/block/escalate thresholds. The gateway separately enforces the result: ingress precedes effects, and egress evaluates the output that could actually be released.

ALLOW and ALLOW_WITH_WARNINGS may release. REDACTED requires successful transformation and revalidation. BLOCKED and ESCALATE_HITL withhold data. A remediation instruction is an obligation; an enforcement receipt records a completed action. A hold does not itself record human approval.

Bundled coverage

The catalog includes healthcare-pattern, PCI-pattern, security, accessibility-copy, and strict demo packs. Coverage follows enabled validators: the accessibility pack does not include privacy or secrets detection. Pattern checks do not prove complete PHI removal, grounded answers, clinical validity, prompt-injection immunity, or regulatory conformance.

Approved descriptive alignment is a separate authority input. The runtime validates its exact version, digest, lifecycle, reviewer assignments, evidence, and current membership. An active profile still requires executable capability support; unsupported semantics remain held.

Guided comparisons and overrides

Guided scenarios use server-selected synthetic fixtures and versioned evaluation tiers bound to the configured demo application. Their expected teaching labels are separate from measured validator and enforcement results. Raw fixture diagnostics remain visible for comparison; freeform content does not inherit fixture authority.

Sandbox override categories, scope limits, TTLs, and review exercises simulate exceptional workflows. They do not authorize production release, execute arbitrary tools, or satisfy clinical review. Current clinical, regulatory-evidence, and generated-code profiles remain explicitly unsupported.

See Policies & validators for the implemented catalog, API for release contracts, and Enterprise readiness for current qualification limits.