ProdgatorDocs
GatesRelease policies

Draft a policy with AI

Describe a release policy in plain words; the assistant writes form rules or Rego with tests, and only a draft whose tests pass can be loaded into the editor.

Availability

Business plan and above with release policies, and AI features with Policy drafting assistant turned on for your organization. Drafting needs the same permission as writing policies (the role, or a custom role that may write policies).

The policy editor has a Draft with AI button. Describe what the policy should decide, and the assistant writes a draft with its tests, checks it, and hands it to the editor as unsaved changes. Each draft costs 5 AI credits, however many repair rounds it took.

Writing a draft

  1. Open a new policy, or an existing one, in the editor and click Draft with AI.
  2. Describe the policy, for example "require two approvals from the Release managers group before a release to a protected environment".
  3. Choose Let AI choose, Form rules or Rego. Form rules are preferred whenever they can express the request; Rego (OPA v1 syntax) is used when they cannot, or when you ask for it.
  4. Click Generate and review the result: an explanation, the assumptions the model made, a preview of the rules or the Rego modules and their tests, and the check result.
  5. Click Load into editor. The draft replaces what is in the editor as unsaved changes. Review it, then save it the usual way.

When you draft from an existing policy, the model gets the policy as it stands in the editor (unsaved edits included) and changes it as you asked, keeping what you did not mention.

What the model gets

Your request, the policy currently in the editor, the names and ids of your approver groups, the names and emails of up to 200 organization members (so rules can name people and groups by id), and a description of the input document policies read. All of it is passed as data: a group or member name is never an instruction.

Every draft is checked

Before you can load it, a draft must:

  1. Validate: pass the same checks the editor runs when you save.
  2. Compile: build with the policy compiler, with nothing written anywhere.
  3. Test: pass at least one generated file covering a passing and a failing case, run with .

A draft that fails is sent back to the model with the errors, up to three rounds, and then once more to a stronger model when one is configured. If the last round still fails, the dialog lists the errors by file and line and Load into editor stays disabled. Rewording the request and generating again often helps.

Observe first

A loaded draft is always in Observe mode, so a draft saved by mistake can never block a release. Switch the policy to Enforce in the editor once you have reviewed it.

What the assistant never does

  • It never saves. Nothing reaches your policies until you click Save in the editor.
  • It never writes policies that need data the input document does not have: change tickets, deployment windows, calendars or other external systems. For those it answers that the request cannot be drafted, with the reason.
  • It never writes custom Rego rules inside a form policy; a Rego draft is a whole Rego policy for the release subject.

On this page