Docs

Decisions

Review policy decisions produced by governed AI activity.

Decisions is the log of every policy verdict governed AI activity has produced — one browsable, filterable record per invocation, sourced from the telemetry module rather than the policy module (which only computes the verdict; this is where it's recorded and reviewed).

A row joins a decision to its invocation: subject, target tool or action, MCP server, the decision itself, the rules that matched, and a timestamp. The log can be filtered by subject, and the same read path backs a tenant's aggregate allow/deny counts.

Two follow-on actions live on each row. Replay deep-links the row's subject, subject type, action, and MCP server into Gateway Test as URL parameters, so the exact same call can be re-run live and re-checked against whatever the policy set looks like now. Identity Chain opens a single invocation as a six-step view — Human, IAM Role(s), Agent, MCP Server, Tool Call, and Resources/Outcome — built from one aggregating read that joins the invocation to its agent, server, matched-rule targets, and edge mode, resolving table/column names and sensitivity flags for whatever the call actually touched. Steps 1–2 (human, IAM role) come from the customer's own identity provider; steps 3–6 are what FaburAI governs, and the page visually distinguishes the two.

A decision resolves to allow, deny, or oblige — recorded on the decision row itself — with the log's own aggregate stats currently surfacing allow and deny counts.

Reference

Features

Decisions Log
description
Lists every recorded policy decision — one row per invocation, joined to its subject, target tool, MCP server, and matched rules — filterable by subject.
Allow and deny outcomes
description
Each decision resolves to allow, deny, or oblige; the log's aggregate stats currently surface allow and deny counts for a tenant.
Replay
description
Deep-links a past decision's subject, subject type, action, and MCP server into Gateway Test so the same call can be re-run live against the current policy set.
Identity chain
description
Opens a single invocation as a six-step chain — Human, IAM Role(s), Agent, MCP Server, Tool Call, and Resources/Outcome — joining the invocation to its agent, server, and matched-rule targets in one read.

Interfaces

data-plane serves /enforcement-logs
data-plane serves /enforcement-logs/:traceId/replay
data-plane serves /identity-chain/:invocationId