A little help. A clear record.
dyna.ai - Conversation policy ontology
Build a bot. Agree its boundaries. Follow the evidence.
Your organisation. Your operating rules. Build lending and servicing workflows with reviewed policies, controlled access and a record of the decisions behind the work.
Conversation policy ontology
The Conversation Cedar namespace governs actions inside a conversation. Call placement uses its separate admission policy. Passing call admission does not grant the conversation permission to retrieve protected facts, speak them, invoke a tool, record audio or transfer a call.
Entities and actions
| Cedar entity | Identifier |
|---|---|
Conversation::Agent |
Pinned bot version, or the pinned draft test identifier |
Conversation::Call |
Exact retained call identifier, or the scoped draft-test call identifier |
The supported actions are continueConversation, discloseProtectedInformation, retrieveProtectedKnowledge, invokeTool, recordAudio and transferCall. The principal is an Agent and the resource is a Call for every action.
Authoritative context
Every context field below is Boolean and required. The server constructs these facts from retained state. A visitor, model, prompt or scenario form cannot submit them as trusted assertions.
| Fact | Meaning |
|---|---|
session_active |
The exact tenant session is active and within its expiry. |
consent_current |
A current permission receipt matches this tenant, session, call and subject. |
generation_current |
The request belongs to the current execution generation. |
identity_current |
An approved issuer's signed verification matches this tenant, call, subject and generation and has not expired. |
recipient_allowed |
The verified recipient role is in the configured approved role set. |
protected |
The action, node, tool or retained conversation context contains protected information. |
tool_approved |
The enabled server tool belongs to this pinned graph and current node. |
recording_consent |
A current call-bound receipt explicitly permits recording. |
transfer_approved |
The destination is approved for this tenant and graph and belongs to the current consent generation. |
Baseline rules
The built-in policy permits an action only while the session, consent and generation are current. It forbids protected activity when current identity or an allowed recipient is missing. It separately forbids unapproved tools, recording without recording permission and unapproved transfers.
For example, the disclosure gate is executable Cedar:
cedar
forbid(principal, action, resource)
when {
context.protected &&
(!context.identity_current || !context.recipient_allowed)
};
A reviewed active enterprise action policy must also allow the request. Its schema, source, content hash and effective interval remain part of the retained decision. Missing facts, invalid policy or evaluation errors deny the action.
Identity and recipient roles
Verification includes an issuer version, approved method, exact subject, call, session, tenant, generation, issue time, expiry and evidence reference. An issuer configuration change invalidates earlier assertions. Caller ID, phone possession, a self-declaration and an LLM classification are not accepted methods for protected customer identity.
An organisation configures the permitted recipient roles with its reviewed interpretation. Do not assume that the consumer is the only legally permitted recipient, or that any person describing themselves as an attorney is authorised. Verify the applicable relationship before disclosure. The federal communication rule includes recipient definitions and exceptions that need to be considered with state requirements. See 12 CFR 1006.6.
When verification is absent, the runtime withholds protected context and blocks protected speech. The approved conversation should use a neutral response and stop or request human assistance. The refusal must not itself reveal the protected facts.
Variables, knowledge and tools
Graph variables have a declared type and an explicit protected classification. Protected values must not enter model context before the required identity and disclosure admission. Public classification is a deliberate data-design choice. It is not a way to bypass a legal requirement.
Knowledge points to immutable published Frappe versions. Retrieval checks the current session and source permissions. A protected retrieval keeps the conversation protected for later turns. Switching to a public node does not remove that retained protection.
Tools belong to a static server registry. Their argument schema, protected status and enablement are server-owned. A model can propose a declared action. It cannot add an arbitrary URL or function. A successful database tool receipt and its business record are committed together. Repeating the same operation must not create a second business record.
Revocation and evidence
Identity replacement, identity revocation and consent withdrawal change the generation where required. The runtime rejects stale actions and clears queued speech when it acknowledges the stop. Record the acknowledgement separately from the request so a review can distinguish what was requested from what the runtime confirmed.
Retain the action, policy version, generation, decision, relevant fact results and operation identifiers. Do not treat a generated summary as the original evidence.
Source-governed recipient controls
RecipientControl is a separate Cedar namespace for source-derived restrictions on conversation actions. Its rule schema is conversation-recipient-controls-1. An active mapping is evaluated alongside the mandatory conversation guard and the reviewed enterprise action policy. Every applicable layer must allow the action.
The mapping records its citation, source snapshot and hash, reviewed interpretation, exact compiled Cedar and manifest. Open Policies in the workspace to inspect those records. The Rhode Island mapping concerns communication recipients under R.I. Gen. Laws § 19-14.9-5. It does not determine every requirement that applies to debt collection.
The compiler declares RecipientControl::Agent, RecipientControl::Call and the same six action names listed above. Its generic rule evaluation uses RecipientControl::Agent::"agent" and RecipientControl::Call::"call". The application independently binds each evaluation to the actual tenant, session, call, bot version, generation and manifest. A generic Cedar entity identifier is not a substitute for those checks.
All nine recipient context fields are required Booleans:
| Fact | Server meaning |
|---|---|
applicable |
The retained business jurisdiction is Rhode Island. Unknown jurisdiction cannot be treated as outside scope. |
scope_known |
Current server-held business scope matches this tenant, session, call and Mission. |
source_current |
The mapping is active, its source is current, and its source and manifest hashes pass verification. |
identity_current |
A current version-two assertion verifies the named recipient for this exact scope and generation. |
relationship_current |
Verified relationship evidence matches the consumer, debt, creditor and collector references. |
recipient_role_allowed |
The verified role is included in the reviewed mapping. |
special_authority_current |
Any additional authority required for that role is present. A reporting-agency role requires a separate permission digest. |
wrong_party |
A retained negative recipient event restricts this conversation. |
debt_communication |
The requested action is debt communication rather than an admitted fixed neutral template. |
The generated restriction is:
cedar
permit(principal, action, resource);
forbid(principal, action, resource) when {
context.debt_communication && (!context.scope_known ||
(context.applicable && (!context.source_current || !context.identity_current ||
!context.relationship_current || !context.recipient_role_allowed ||
!context.special_authority_current || context.wrong_party)))
};
The reviewed role list can select consumer, consumer_spouse, consumer_parent_of_minor, consumer_guardian, consumer_executor, consumer_administrator, consumer_attorney, consumer_reporting_agency, creditor, creditor_attorney and collector_attorney. A parent role requires verified minor status. Consumer identity must match the retained consumer reference. Naming a relationship in the conversation does not verify it.
Direct consumer consent, court permission, post-judgment remedies and location-information exceptions are recorded as unsupported routes in this workflow. This is a narrower operating restriction. The application does not infer or grant an exception from free text.
Communication modes and trusted evidence
An agent node may use debt_communication, neutral_verification or neutral_closure. The neutral modes use approved fixed templates with no model prompt. They cannot retrieve knowledge, interpolate protected values or invoke tools. A collections model node defaults to debt communication even when a graph author marks its ordinary variables as unprotected.
Business scope contains four nonempty references: consumer, debt, creditor and collector. A version-two assertion adds the verified recipient, role, relationship_evidence_hash, consumer_is_minor and optional special_permission_hash. Its issuer must be configured for version-two authority and a permitted verification method. Scope, issuer configuration, time and generation are checked again before protected activity.
A wrong-party event changes the generation, invalidates identity and clears queued speech. The runtime may deliver only its approved neutral closing before termination. Withdrawn or expired consent permits no further audio. Audit the stop acknowledgement separately from its request.
An owned_fixture mapping pins exact published bot versions. The server also checks the actual owned endpoints and Mission/Call binding. Its dedicated fixture-scope account can record only negative-test context. Such a fixture always remains unverified, even if another issuer assertion is present. Fixture activation does not establish customer recipient authority and is excluded from customer coverage on the map.