Policy not loaded

Overview

Your gateway, active controls and recent traffic.

Get connected

Connect your workspace

Connect your workspace to inspect the active configuration and manage policies.

1

Connect your identity

Use a management credential to view and change policies. Add an agent credential to send requests.

2

Set your policy

Describe a rule or configure controls directly. Review changes before activating them.

3

Verify a request

Send your own input through the gateway and inspect the decision in Activity.

Requests
—
Since this instance started
Allowed
—
Completed without redaction
Blocked
—
Input or output denied
Redacted
—
Sensitive content transformed
Errors
—
Failed protected invocations
Requests / second
—
Recent instance traffic
Local-only path
—
No semantic stage · since startup
Semantic path
—
At least one assessment stage · since startup
Latency · p95
—
Includes upstream, excludes gateway transport

Top denial reasons

Recent loaded activity only

Connect a management identity to inspect recent denials.

Active controls

Policy —
Privacy · input / outputNot loaded
Threat signaturesNot loaded
Content rulesNot loaded
Semantic analysisNot loaded

Connect a management identity to inspect active controls.

Configuration status

Configuration status is available after connecting a management identity.

Source—
Last checked—

Changes apply to new requests. Requests already in progress finish using their original policy version.

Resource usage

Per identity · UTC day

Connect a management identity to view resource usage.

Budgets and retained audit records are local to this process and reset when it restarts.

Connect your workspace

Use management access to configure FastFence. Add agent access when you want to send test requests.

Can view policies and audit, and activate configuration changes.

Can execute model and tool calls. Existing connections are kept when a field is blank.

New credentials are in state/credentials.json. Existing installations keep their original file. Tokens are never stored in your browser's local storage.

Saved semantic regression tests

Replay the saved expectations against the active policy using real Laya. This does not activate or modify policy. No business model or tool is executed.

Add a Laya rule

Write what must be blocked in plain language. Laya evaluates the meaning of content against this rule on every applicable request.

Expected outcomes

Use synthetic examples. Each nonblank line is tested in every selected direction and target. Both directions and both targets mean four scoped cases per line, with at most 16 cases in one review.

Rule / scopeExampleExpectedActive policyProposed policyResult

Exact policy change

These checks assess only semantic policy. They do not execute business models or tools and do not test access, budgets or other controls. Passing examples do not establish general detection accuracy. Exact text rules remain preferable for literal words or letters.

Edit policy settings

1. Edit settings → 2. Review changes → 3. Activate. Changes take effect without restarting the gateway.

Privacy controls

Semantic content analysis

Evaluate the meaning of input and optional output text. Laya runs the configured model for each semantic check; deterministic rules remain the fastest path. Errors and timeouts fail closed.

Severity is an ordinal category: benign 0, suspicious 0.6, malicious 1. It is not a probability. Test your policy on representative permitted and prohibited content.

Anonymization

Reversible mode requires a configured keyring. Restoration also requires permission on the rule and an explicit request.

Advanced configuration: models, tools, limits and complete policy

Use this editor for settings outside the form. Version is managed automatically.

Add text rule

Define a match, test it on your own samples, then review and activate.

Only U+200B, U+200C, U+200D, U+2060 and U+FEFF are ignored. Disabled by default because joiners can change language or emoji meaning. Original content is unchanged.

Matching content is blocked. Output checks happen after the upstream call. Accents remain distinct; a does not match ą.

Exact rule change

Active

Proposed

Anonymization rule

Matching values receive distinct, stable aliases. Review the full policy change before activating.

This enables anonymization. Recovery mode is configured in policy settings; permission here does not switch it to reversible mode.

Create a policy change

Describe a policy

Step 1 of 4 · Describe the change

Laya drafts a bounded policy change once. FastFence enforces the resulting controls locally.