Review policy decisions
Every time a governance policy evaluates a request, Creatio AI Studio records a decision. The Decisions section is that audit trail: what a policy flagged, masked, or gated, when, and how it was resolved.
Use it to prove a policy is doing its job — and to find out why an agent behaved the way it did.
Decision results
Result | Meaning |
|---|---|
Transformed | The policy rewrote the payload before the model ran. This is what a PII protection policy in Enforce mode records. |
Observed | The policy matched but changed nothing. This is what a policy in Observe mode records. |
Approval requested | The policy paused the action and routed it to a human reviewer. |
Blocked | The policy refused the action outright. |
Stopped | The run was halted. |
Restored | Tokenized values were put back into the outbound reply. |
Find a decision
-
Go to the Decisions section under Trust & Governance in the navigation panel.
-
Narrow the list using the filters.
- Agent — a single agent, or "All agents." Select "Global" to see decisions from policies that are not scoped to one agent.
- Result — "All," "Approval requested," "Transformed," or "Observed." The other results in the table above are recorded on a decision but cannot be filtered for.
- Outcome — how the paired approval was resolved: "Pending," "Approved," "Rejected," "Rejected with retry," "Rejected with feedback," "Auto-rejected (timeout)," or "Not applicable."
- Search — free-text search across the decisions.
-
Open a decision to see its detail.
As a result, the list narrows to the decisions you need. When nothing matches, Creatio AI Studio reports "No decisions match your filters."
Read a decision
A decision page is organized into the following sections.
Section | What it holds |
|---|---|
Overview | The Result, Mode, Severity, and Time of the decision. |
Context | Reference metadata: the agent, the tool, the run, the policy, and the scope that matched. Click Open run to jump to the run trace. |
Evidence trail | The recorded evidence, including the detected entities for a PII decision. |
Arguments | The tool arguments captured at the moment the policy was evaluated. |
Confirmation routing | For a risky-tool gate: the routing mode, the timeout in minutes, and whether the request falls back to an admin when no chat is available. |
Approval outcome | How the paired approval was resolved, who decided it, and through which surface — "Admin UI," "In-session chat," or "System." A decision recorded in Observe mode, or by a policy that does not gate, reports that no approval was required. |
Verify that a PII policy is masking
A PII policy runs before the model, so the proof is in the model input rather than the agent's reply. Check both.
- Open the agent the policy is scoped to.
- Go to the Preview panel and turn on Show trace.
- Send a message that contains obviously fake values of the entity types the policy covers.
- Read the model input in the trace, not only the agent's answer. A masked value appears as its placeholder, for example, "[EMAIL]," "[PHONE]," or "[PAYMENT_CARD]."
- Go to the Decisions section and open the newest decision for that agent. It records the result as "Transformed."
As a result, you have both halves of the evidence: the trace shows the model never received the raw value, and the decision log records that the policy acted.
You can also open the run in the Observability section: in its Execution timeline, each PII protection check appears next to the model call it preceded.
Read the trace against the policy's entity list rather than assuming full coverage. When Hide original values from audit log is turned on, the decision proves the value was masked without storing the raw value — evidence without a second copy of the data you were protecting, which is the intended state for production.
Only the entity types you selected in the policy are masked. An entity you left unselected passes through untouched — a bank account number stays visible if you selected only email, phone, and payment card.