Skip to content

Policy packs

A policy pack is a set of pre-compiled mandates applied to a workspace in one step. Packs go through the normal Charter path: every mandate compiles to enforcement rules, backtests against the last 30 days, and seals to the Provenance Vault. They are applied in shadow mode by default, so nothing changes until you promote a mandate in Authority → Charter.

Packs encode technical controls, not legal conclusions. Each mandate lists the framework clauses a compliance team may cite as evidence (controls), and that mapping lives outside the runtime decision (compliance mapping and runtime policy are kept separate by design).

Pack Mandates Typical use
pilot-starter Large payments (SAR 500k) need approval, Saudi PII never leaves the organisation, destructive operations refused Every pilot workspace
saudi-enterprise Data residency (classified data only to destinations declared inside SA), external model access, Saudi identifiers (National ID, Iqama, mobile, IBAN, CR), supervised exports and admin actions Saudi enterprises (PDPL-shaped)
saudi-financial Payment authority (approval above SAR 100k, refused above SAR 1M), account/card/IBAN disclosure, customer communications that change a financial decision SAMA-regulated institutions, on top of saudi-enterprise

Applying a pack

Xybern applies packs when provisioning a workspace (admin console → New workspace → Policy pack) or later:

POST /api/admin/workspaces/<workspace_id>/apply-pack   {"pack_id": "saudi-enterprise", "mode": "shadow"}

Applying is idempotent: mandates that already exist (same outcome text) are skipped.

How residency is evaluated

The residency mandate is deterministic (no LLM): it reads the metadata your agents send with each action.

{"action_type": "data.transfer",
 "metadata": {"classification": "RESTRICTED", "destination": {"region": "US"}}}

is refused; the same action with "destination": {"region": "SA"} proceeds; a classified action with no destination declared is refused (unknown is not inside the Kingdom). Public and internal classifications are unaffected. Use classification (PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED, or tags such as PII, FINANCIAL, HEALTH) and destination.region (or a flat region) in your metadata; LLM gateway calls carry provider and model automatically.

Installs without an LLM

With XYBERN_LLM_PROVIDER=none, the semantic guards inside a pack are dropped at apply time (recorded as semantic_dropped) and mandates that consist only of a semantic guard are skipped. Every deterministic control still applies.