Reference
Policies

These are the standing rules the product enforces — not aspirations. Each maps to a concrete enforcement point: an engine check, a blocking gate, or a governed review path. The narrative version, with the reasoning behind each position, is at Design Principles.
Sources & ingest
| Policy | What it enforces |
|---|---|
| Feeders feed, they never author | Application and software inventories carry attribution evidence but can never create device records. Only trusted discovery sources mint new CIs. |
| Authoritative source owns each attribute | Per-attribute precedence, authored from evidence at onboarding, recorded field-by-field with the values it beat. |
Identity
| Policy | What it enforces |
|---|---|
| No hopeful imports | Records below the identity bar are blocked with the specific reason stated — a record you cannot identify is a scheduled duplicate. |
| Conflicts surface, never absorb | One-serial-many-hosts and one-host-many-serials are flagged for review; silent merging is prohibited. |
Classification
| Policy | What it enforces |
|---|---|
| Deployable leaf classes | Automatic classification targets only deployable leaf classes; abstract parents are rejected as rule targets at authoring, deployment, and runtime. |
| Collision-guarded rules | Rule authoring checks substring predicates against observed values across all sources; consumer-platform rules require a corroborating condition. |
| Doubt routes to review | Records the rules cannot place with confidence go to a review queue with evidence — never into a catch-all default. |
CSDM attribution
| Policy | What it enforces |
|---|---|
| Content evidence anchors confirmation | A placement is confirmed only on evidence found on the device itself; context can corroborate, never anchor; structural defaults never confirm. |
| Zero false confirms on the evaluation corpus | No engine release ships unless validation demonstrates zero false confirmations; operator confirms and rejects continuously feed the gate’s labels. |
| Endpoints park honestly | End-user devices attach to the management service that operates them — not force-attributed to business services on weak signals. |
| Coverage is three numbers, not one | Business-attributed / management-service / unassigned, computed by one shared predicate everywhere it appears. |
| Emission is staged; capture never is | What ships grows with adoption stage (crawl/walk/run/fly); what the system learns is never gated; promotion is an operator decision on the record. |
| The workbook is a view | The CSDM 5.0 workbook is generated from the governed model; hand-edited spreadsheets are never a source of truth. |
Export
| Policy | What it enforces |
|---|---|
| IRE-ready payloads, never table loads | Everything arrives at the instance as conditioned input to Identification and Reconciliation. Export quality gates block bundles that fail their checks. |
Governance
| Policy | What it enforces |
|---|---|
| The system authors, the operator reviews | Configuration is AI-authored with rationale onto the decision record; operator overrides are first-class, attributable, and take precedence. |
| Recommend, don’t assert | Every recommendation carries a confidence band, evidence, and review status; low-confidence inferences become questions, never silent facts. |
| Every engine change is regression-proven | Changes ship only after verification against pinned full-run baselines — byte-identical, or the difference is explained. |
| Data stays home | Single-tenant deployment in your environment; discovery data never leaves it. |
Honesty note
Policies differ in how they are held: most are engine-enforced or gate- blocking; a small number are review-doctrine applied by the governed authoring path. We track the difference internally and promote doctrine to engine enforcement as the machinery lands.
All docs
OverviewGolden records & identitySource precedenceClassificationEvidence & reasoningUncertainty & failure modesField coverage & gapsAdoption stagesThe CSDM 5.0 modelAttribution & coverageQuality & scopeConductor & ProGovernance decisionsThe decision recordReview & overridesDeliverablesThe import packageGlossaryPoliciesDiscovery sourcesDeployment model