Use cases· Last updated

Compliance decision workflow with Jev

SOC 2 / ISO rows have owners, cadence, and pass/fail. Jev can flag “this evidence blob never mentions production.” The control owner still attests. Jev is not the auditor and not the GRC system of record.

This unofficial page is the decision workflow slice of the compliance evidence pre-score pack. Intent: apply the Jev (TypeSafe System One) decision model to compliance evidence pre-score decision workflow. Primary search language: Compliance Jev decision workflow. Confirm patterns on docs.typesafe.ai. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.

Independent angle (cover ≠ clone): Checklist is the control; Jev pre-scores whether evidence language looks complete. Owner still signs — not a GRC-clone or rival checklist-IA photocopy. Fan-out extra atoms on one request; open a second HTTP call only for a new artifact, not the same state.

Compliance use-case context

Compliance evidence pre-score is a workflow, not a chat. Assemble a narrow state, ask the primitives below, and let the GRC pre-scorer branch. TypeSafe’s docs say a good question is a snap decision a knowledgeable person could make in a few seconds — not an open-ended analysis of the control prompt + evidence blob.

Hub: Use cases. Compare, when the other tool is the real job: compliance checklists.

Decision Workflow inputs

Keep only fields the questions name:

{
  "control": { "id": "CC-6.1", "prompt": "Evidence must describe production access reviews this quarter." },
  "evidence": { "title": "Access review export", "text": "We reviewed staging users in January." },
  "policy": { "env": "Staging-only language is a gap for production controls." }
}

Point instructions at control.prompt, evidence.text, policy.env. Drop screenshots (describe them in text first); the entire SharePoint site.

Decision signals and actions

Id Type Job
mentions_prod Noul Does evidence.text address production as required by control.prompt / policy.env?
completeness Score How complete does the blob look vs the control prompt?
next Choice ready_for_owner / gap / owner_review / other

All of these share state and run in parallel. Code owns the graph:

def compliance_prescore(ans):
    if ans["mentions_prod"].noul < T_PROD:
        return "gap"
    if ans["next"].confidence < FLOOR or ans["next"].choice == "other":
        return "owner_review"
    return ans["next"].choice

Do not treat a Noul of 0.5 as a “medium” compliance evidence pre-score score — it means yes and no are equally likely. Conjunctions stay in your code.

Guardrails and escalation

TypeSafe’s confidence-gated examples use a lower bar for recoverable reads than for irreversible actions. Those numbers are illustrations. For compliance evidence pre-score, treat mark_control_passed as the high bar (marking a control passed or signing attestation). Tune on labels — see offline evaluation.

Low confidence, or a policy miss → human or safe default; do not mark the control passed.

Evaluation and rollout notes

Shadow: GRC status unchanged; show Jev next to the owner.

Canary: Nudge-only on one low-risk control family. Never auto-pass.

Pin jev-1.13.0 (the versioned id) after you fit thresholds. jev-latest and the marketing line jev-1.13 can move. Log the response model. TypeSafe’s published list price for jev-1.13 is $0.042 per million input tokens (vendor claim — confirm on the models page); output tokens are free on that same page. Unused distractors still bill as input.

Official Python and JavaScript SDKs read TYPESAFE_API_KEY and retry documented 429/529. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.

Pack map

Slice Page
Graph and primitives you are here
What may enter state input contracts
What to gather first evidence collection
Atomic rules policy checks
Act / review / abstain confidence thresholds
Reviewer payload human handoff
What to persist audit trail
How it breaks failure modes
Labeled replay evaluation
Shadow → canary production rollout

FAQ

Does Jev execute the GRC pre-scorer action? No. It returns typed answers. Your GRC pre-scorer code calls queues, models, or humans.

Why several questions in one request? TypeSafe’s fan-out pattern: extra questions are cheap versus another HTTP call. mentions_prod + completeness + next in one call. Extra Nouls (dates mentioned? sampling described?) are cheap vs another HTTP trip.

Where is the rest of the Compliance pack? Start with Compliance input contracts and Compliance confidence thresholds. Cluster hub: Use cases.

Can Jev be our auditor? No. It pre-scores language. Owners and auditors sign. See governance.

May we send screenshots? Not as images. Transcribe what the screenshot shows, then ask snap questions.

What this page does not claim

Disclaimer

This is an independent unofficial site and is not affiliated with TypeSafe AI; official documentation is available at https://docs.typesafe.ai.

Primary documentation: https://docs.typesafe.ai. Hub: Use cases.

Sources

Public TypeSafe or adjacent documentation only. No private claims.