Skip to content
Service status

Type to search

Governance · 1 min read

Policies

Organization-wide rules the platform enforces automatically, whoever is using it.

A policy is a rule the platform enforces itself. Rather than relying on every user making the right choice, or on an administrator noticing afterward, a policy makes the behavior a property of the system.

A permission decides who is allowed to do something. A policy decides what happens regardless of who’s involved — it isn’t a gate one role can pass and another can’t, it’s a rule that applies uniformly.

Allow or disallow space members with edit access from viewing Assistant Insights across your organization. Turning this off hides Insights on every assistant it currently applies to, not only new ones.

Set the longest period, in days, that conversations and related data may be stored anywhere in your organization. Once set, no assistant’s own retention setting can exceed it — see Data retention policy for how the two interact.

Set the regions in which data carrying a given security classification may be processed, per classification. A model whose sub-processor is hosted outside them stops being offered in Spaces with that classification, and the regions apply to completion, embedding, transcription and image models alike.

This is a separate test from whether a model is classified highly enough — a model can be approved for the classification and still be unavailable because of where it runs. See Processing regions for how classifications, models and sub-processors fit together.

Before you confirm a change, Intric shows you its impact. It might tell you how many assistants currently retain conversations longer than a new maximum you’re about to set, or how many currently have Insights visible that a change would hide.

Where a policy blocks something a user might otherwise expect to do — viewing Insights, say — the interface explains why. It names your organization’s policy as the reason, rather than showing a generic error.

A policy can be marked deprecated once your organization no longer needs it, without removing its history from the record of what was configured and when.