A building block

A little help. A clear record.

dyna.ai - Conversation policy ontology

Build a bot. Agree its boundaries. Follow the evidence.

Your organisation. Your operating rules. Build lending and servicing workflows with reviewed policies, controlled access and a record of the decisions behind the work.

Conversation policy ontology

The Conversation Cedar namespace governs actions inside a conversation. Call placement uses its separate admission policy. Passing call admission does not grant the conversation permission to retrieve protected facts, speak them, invoke a tool, record audio or transfer a call.

Entities and actions

Cedar entity Identifier
Conversation::Agent Pinned bot version, or the pinned draft test identifier
Conversation::Call Exact retained call identifier, or the scoped draft-test call identifier

The supported actions are continueConversation, discloseProtectedInformation, retrieveProtectedKnowledge, invokeTool, recordAudio and transferCall. The principal is an Agent and the resource is a Call for every action.

Authoritative context

Every context field below is Boolean and required. The server constructs these facts from retained state. A visitor, model, prompt or scenario form cannot submit them as trusted assertions.

Fact Meaning
session_active The exact tenant session is active and within its expiry.
consent_current A current permission receipt matches this tenant, session, call and subject.
generation_current The request belongs to the current execution generation.
identity_current An approved issuer's signed verification matches this tenant, call, subject and generation and has not expired.
recipient_allowed The verified recipient role is in the configured approved role set.
protected The action, node, tool or retained conversation context contains protected information.
tool_approved The enabled server tool belongs to this pinned graph and current node.
recording_consent A current call-bound receipt explicitly permits recording.
transfer_approved The destination is approved for this tenant and graph and belongs to the current consent generation.

Baseline rules

The built-in policy permits an action only while the session, consent and generation are current. It forbids protected activity when current identity or an allowed recipient is missing. It separately forbids unapproved tools, recording without recording permission and unapproved transfers.

For example, the disclosure gate is executable Cedar:

cedar forbid(principal, action, resource) when { context.protected && (!context.identity_current || !context.recipient_allowed) };

A reviewed active enterprise action policy must also allow the request. Its schema, source, content hash and effective interval remain part of the retained decision. Missing facts, invalid policy or evaluation errors deny the action.

Identity and recipient roles

Verification includes an issuer version, approved method, exact subject, call, session, tenant, generation, issue time, expiry and evidence reference. An issuer configuration change invalidates earlier assertions. Caller ID, phone possession, a self-declaration and an LLM classification are not accepted methods for protected customer identity.

An organisation configures the permitted recipient roles with its reviewed interpretation. Do not assume that the consumer is the only legally permitted recipient, or that any person describing themselves as an attorney is authorised. Verify the applicable relationship before disclosure. The federal communication rule includes recipient definitions and exceptions that need to be considered with state requirements. See 12 CFR 1006.6.

When verification is absent, the runtime withholds protected context and blocks protected speech. The approved conversation should use a neutral response and stop or request human assistance. The refusal must not itself reveal the protected facts.

Variables, knowledge and tools

Graph variables have a declared type and an explicit protected classification. Protected values must not enter model context before the required identity and disclosure admission. Public classification is a deliberate data-design choice. It is not a way to bypass a legal requirement.

Knowledge points to immutable published Frappe versions. Retrieval checks the current session and source permissions. A protected retrieval keeps the conversation protected for later turns. Switching to a public node does not remove that retained protection.

Tools belong to a static server registry. Their argument schema, protected status and enablement are server-owned. A model can propose a declared action. It cannot add an arbitrary URL or function. A successful database tool receipt and its business record are committed together. Repeating the same operation must not create a second business record.

Revocation and evidence

Identity replacement, identity revocation and consent withdrawal change the generation where required. The runtime rejects stale actions and clears queued speech when it acknowledges the stop. Record the acknowledgement separately from the request so a review can distinguish what was requested from what the runtime confirmed.

Retain the action, policy version, generation, decision, relevant fact results and operation identifiers. Do not treat a generated summary as the original evidence.

Source-governed recipient controls

RecipientControl is a separate Cedar namespace for source-derived restrictions on conversation actions. Its rule schema is conversation-recipient-controls-1. An active mapping is evaluated alongside the mandatory conversation guard and the reviewed enterprise action policy. Every applicable layer must allow the action.

The mapping records its citation, source snapshot and hash, reviewed interpretation, exact compiled Cedar and manifest. Open Policies in the workspace to inspect those records. The Rhode Island mapping concerns communication recipients under R.I. Gen. Laws § 19-14.9-5. It does not determine every requirement that applies to debt collection.

The compiler declares RecipientControl::Agent, RecipientControl::Call and the same six action names listed above. Its generic rule evaluation uses RecipientControl::Agent::"agent" and RecipientControl::Call::"call". The application independently binds each evaluation to the actual tenant, session, call, bot version, generation and manifest. A generic Cedar entity identifier is not a substitute for those checks.

All nine recipient context fields are required Booleans:

Fact Server meaning
applicable The retained business jurisdiction is Rhode Island. Unknown jurisdiction cannot be treated as outside scope.
scope_known Current server-held business scope matches this tenant, session, call and Mission.
source_current The mapping is active, its source is current, and its source and manifest hashes pass verification.
identity_current A current version-two assertion verifies the named recipient for this exact scope and generation.
relationship_current Verified relationship evidence matches the consumer, debt, creditor and collector references.
recipient_role_allowed The verified role is included in the reviewed mapping.
special_authority_current Any additional authority required for that role is present. A reporting-agency role requires a separate permission digest.
wrong_party A retained negative recipient event restricts this conversation.
debt_communication The requested action is debt communication rather than an admitted fixed neutral template.

The generated restriction is:

cedar permit(principal, action, resource); forbid(principal, action, resource) when { context.debt_communication && (!context.scope_known || (context.applicable && (!context.source_current || !context.identity_current || !context.relationship_current || !context.recipient_role_allowed || !context.special_authority_current || context.wrong_party))) };

The reviewed role list can select consumer, consumer_spouse, consumer_parent_of_minor, consumer_guardian, consumer_executor, consumer_administrator, consumer_attorney, consumer_reporting_agency, creditor, creditor_attorney and collector_attorney. A parent role requires verified minor status. Consumer identity must match the retained consumer reference. Naming a relationship in the conversation does not verify it.

Direct consumer consent, court permission, post-judgment remedies and location-information exceptions are recorded as unsupported routes in this workflow. This is a narrower operating restriction. The application does not infer or grant an exception from free text.

Communication modes and trusted evidence

An agent node may use debt_communication, neutral_verification or neutral_closure. The neutral modes use approved fixed templates with no model prompt. They cannot retrieve knowledge, interpolate protected values or invoke tools. A collections model node defaults to debt communication even when a graph author marks its ordinary variables as unprotected.

Business scope contains four nonempty references: consumer, debt, creditor and collector. A version-two assertion adds the verified recipient, role, relationship_evidence_hash, consumer_is_minor and optional special_permission_hash. Its issuer must be configured for version-two authority and a permitted verification method. Scope, issuer configuration, time and generation are checked again before protected activity.

A wrong-party event changes the generation, invalidates identity and clears queued speech. The runtime may deliver only its approved neutral closing before termination. Withdrawn or expired consent permits no further audio. Audit the stop acknowledgement separately from its request.

An owned_fixture mapping pins exact published bot versions. The server also checks the actual owned endpoints and Mission/Call binding. Its dedicated fixture-scope account can record only negative-test context. Such a fixture always remains unverified, even if another issuer assertion is present. Fixture activation does not establish customer recipient authority and is excluded from customer coverage on the map.