Gate

How Gate decides

Updated 4 October 2026

A decision has two layers, in a fixed order.

1. Facts, in code

Amounts, limits, permissions, caps, registered agents, the shape of the request: these are never left to a model. Rules run first and some of them end the decision on their own:

Rule Answer
The actor declared permissions and the action is not among them deny, ACTION_NOT_PERMITTED
The environment enforces registered agents and this actor is unknown, or may not propose this action type deny, AGENT_UNKNOWN / AGENT_NOT_PERMITTED
An action that moves money has no amount more_information, MISSING_AMOUNT
A refund above the environment's limit review, HIGH_VALUE_REFUND
An action type that deletes records, changes bank details or access, or moves data out at least review
The daily decision cap or the monthly budget is reached review, RATE_LIMITED / COST_CAP_REACHED
More content than can be judged review, EVIDENCE_TOO_LARGE

2. Judgment, from the decision model

The remaining proposals go to the decision model with the prepared evidence. The model answers eight questions, each 0 to 1: does the evidence support the action, is it reversible, is a person needed, signs of fraud, data leaving its boundary, data loss, financial impact, blast radius. Rules on those answers set the decision and the reason codes (EVIDENCE_INSUFFICIENT, HUMAN_REVIEW_REQUIRED, FRAUD_INDICATORS, IRREVERSIBLE_HIGH_IMPACT, LOW_CONFIDENCE, …). The answers are returned as semantic, under names that change only with a version.

Fail closed

Any failure of the model, a timeout, a refusal or an unreadable answer is review with PROVIDER_UNAVAILABLE. Never allow, never an error on a well-formed request. A decision that could not be recorded is not answered at all (503 store_unavailable).

Intake: text, HTML, mail and arbitrary JSON

When Intake is on for your environment, the same endpoint reads plain text, HTML (its visible text), a mail message (subject, sender's domain, date, body, attachment names) or any JSON. Code extracts the candidates for the action, the amount and the target; the model only selects among them; what is not there is asked for in missing. Unknown stays unknown: nothing is invented, the order of fields never decides anything, and text that tries to instruct the evaluator is flagged (INJECTION_SUSPECTED). An action type outside the registry is never allowed automatically. Binary documents are not read by Gate itself; a connector such as Control turns them into text first.

Registered agents

An environment can list the agents that may propose and the action types each may propose. In enforced mode an unknown agent or a type outside its list is denied before any judgment. In recorded mode the list is kept for the reports but does not deny.

Caps and budgets

Each environment has a daily decision cap (default 10,000) and a monthly decision budget agreed with Työäly. Both are checked before any model is called; above them the answer is review.

What is kept

The decision record is kept 13 months. The content of a request is kept under the environment's retention mode: full (30 days), redacted, metadata or zero, and never in the record itself. Logs carry ids, sizes, timings and outcomes, never content. Trust and data.

Something missing or unclear on this page? Write to hei@tyoaly.fi.