The compliance platform

From policy and regulation to a gate every agent must pass.

Rulebook is a compiler, registry and compliance decision runtime. It gives every agent one place to check what is allowed, prohibited, required or uncertain before it answers or acts.

One compliance lifecycle

Authoritative requirements in. Policy-governed agent actions out.

Every rule remains linked to source evidence, reviewer confirmation and a published version. Each governed decision creates an auditable trace that remains reproducible even as source material changes.

Decision receipt RB-2048
Agent asks

Can this customer record be shared with the service partner?

Obligations required DecidedGDPR
What was decidedALLOW WITH OBLIGATIONS
Action
Share a customer record with an approved service partner
Caller
customer-support-agent
Context
EU customer · support delivery
Determinism
Same rulebook version and facts reproduce this answer
Pinned to
data-handling@7.4.3 · b3:315921b1…075626807
EvidenceThe exact wording this decision rests on
Data handling policy§ 7.4
Customer records may be shared only with an approved subprocessor for a documented support purpose.
Privacy control standard§ 3.2
Direct identifiers must be redacted before any third-party disclosure.

2 additional controls evaluated and retained in the receipt

How it got there
  1. 01

    Matched the requested action to data-sharing and privacy controls.

  2. 02

    Verified the support purpose and approved partner status.

  3. 03

    Applied the stricter EU customer-data requirements.

  4. 04

    Returned three enforceable obligations before execution.

Signed decision receiptsha256: 7e42a1…91bcVERIFIED

The compliance control loop

Compile. Reason. Enforce. Prove.

Rulebook turns policy and regulatory material into confirmed rules, applies the lowest sufficient reasoning tier, gates the answer or action, and produces audit evidence in the same flow.

Rulebook compliance loopPolicy and regulatory rules become an action-time gate
Published version active
01

Compile

Turn sources into proposals

  • Policies and procedures
  • Contracts and spreadsheets
  • Repositories and standards
Typed rules with source evidence
02

Reason

Climb only when needed

  • T0 deterministic
  • T1 bounded judgment
  • T2 replayable plan
  • T3 labelled explanation
A declared answer tier
03

Enforce

Decide before the action

  • Allow or deny
  • Require approval
  • Return obligations
  • Transform the request
A binding compliance decision
04

Prove

Carry the evidence forward

  • Signed decision receipt
  • Append-only access ledger
  • Independent offline verification
A portable proof record
Human confirms Nothing self-promotesAnswer declares Tier and reproducibilityEvery call Writes a ledger entry

How it works

From source material to a published compliance gate.

01

Connect the requirements

Bring policies, regulations, contracts, spreadsheets and code that define the enterprise's compliance obligations.

02

Compile proposals

Rulebook extracts explicit obligations, conditions, citations, precedence and unresolved conflicts.

03

Confirm and test

Authorized policy, legal and compliance experts inspect proposed rules, run cases and publish an immutable version.

04

Check every decision

Agents call REST, MCP, CLI or SDK interfaces with the context of the proposed answer or action.

05

Gate the action

The gateway enforces allow, deny, obligations or human review before protected tools execute.

06

Verify the audit trace

Every governed outcome can include a signed record tied to inputs, evidence and the published rules that controlled it.

The answer ladder

Use the least intelligence needed.

The caller sets the ceiling. Rulebook climbs only when the tier below cannot answer, never to produce a more fluent response.

T0 · Decided

Symbolic resolution

No model call. The same published version, facts and time produce a bit-reproducible decision path.

Bit-reproducible
T1 · Decided with judgment

Bounded oracles

Approved scalar judgments can narrow or evaluate a condition. Every judgment is recorded verbatim.

Reproducible with recorded judgments
T2 · Reasoned

Validated plan

A model proposes a closed, typed plan. Rulebook validates and executes it without model, network, filesystem or clock access.

Replayable from the stored plan
T3 · Explained

Labelled narrative

An entailment-checked explanation is composed over the T0 to T2 result. It is labelled and never changes the outcome.

Narrative is not reproducible

Human review is an outcome, not a reasoning tier. Missing facts, ambiguity, exceptions or configured policy can require the named authority before an action proceeds.

Compliance control properties

Designed for enforceable, auditable enterprise policy.

  • Unsupported conclusions are not representable as published facts
  • Compiled policy and regulatory proposals require human confirmation
  • Published compliance-rule versions are immutable
  • Model use is visible in the decision record
  • Signed receipts can be verified independently
  • Policy interfaces remain model and agent independent

Deployment and integration

Run on-premises. Connect across every agent stack.

Deploy Rulebook in your data center, VPC or private cloud. Use REST, MCP, CLI and language SDKs to place it at response, tool, approval and workflow boundaries.

Explore integrations

Executive briefing

Put a compliance gate before every consequential AI action.

Bring one consequential agent workflow. We will map the governing policies and regulations, runtime gate, human authority and auditable evidence path with your team.

Request demo