Skip to main content
Part of CLPI Phase 1: Policy Engine. The Policy API is the programmatic interface to policy evaluation.
The Policy API evaluates tool usage against an agent’s resolved policy, and replays historical traces against the current policy for pre-enforcement auditing.
Setting a policy is done through the alignment card. Agent and org policy are not standalone resources — they live in the unified alignment card’s capabilities and enforcement sections. Set an agent’s policy via PUT /v1/alignment/agent/{agent_id}. See Agent cards and the Policy Management guide. The two evaluation endpoints below are the way to test tools against a resolved policy — there is no separate policy CRUD surface.
For authentication, the base URL, rate limits, and the error envelope shared by every /v1/* endpoint, see the API overview and Errors.

Endpoints

POST /policies/evaluate

Evaluate a caller-supplied list of tools against the policy derived from an agent’s published canonical alignment card. Returns a verdict, any violations/warnings/card gaps, and a coverage report.

POST /policies/evaluate/historical

Replay an agent’s most recent traces (up to 200) against its current canonical card, or against a hypothetical card_json, to see which past tool calls would violate today’s policy.
Both endpoints derive the policy from the agent’s canonical alignment card server-side — you never pass a policy document in the request body. See each endpoint’s page for the exact request/response schema, or the Policy Management guide for worked examples.
A related endpoint, POST /teams/recommend-policy, generates a starting policy from a risk forecast rather than evaluating one. See Policy Management → Using policy recommendations.

SDK usage

@mnemom/sdk does not yet include a dedicated helper for policy evaluation. Call /v1/policies/evaluate (or /evaluate/historical) directly over HTTP:

See also