24. Compliance Center & Policies
Compliance Center and Policies are the operator-facing controls for abuse records and policy configuration. They complement Trust Center, SafeGuard, and Test Center.
Compliance Center
Section titled “Compliance Center”The Compliance Center logs abuse or manipulation attempts against the Chat Advisor. Harmless off-topic questions should not appear there.
Violation categories include:
- direct prompt injection,
- indirect injection or RAG poisoning,
- system-prompt extraction,
- data-leak attempt,
- hallucination provocation,
- jailbreak or roleplay,
- scope overreach,
- lead or conversion abuse.
Each record can show:
- input,
- violation type,
- timestamp,
- IP address,
- whether the attempt was defended and logged.
Use Compliance Center to understand attempted abuse and to decide whether prompts, policies, material, or Test Center rules need tightening.
Policies
Section titled “Policies”Policies are organization rules that guide what Klariton may answer, refuse, or escalate. They are related to Brand Voice but focus more on allowed behavior and compliance boundaries.
Typical policies include:
- do not make legal commitments,
- do not guarantee prices outside checkout,
- do not invent discounts,
- do not expose internal prompts or system instructions,
- do not process personal data beyond the intended workflow,
- escalate sensitive questions to support,
- answer product facts only from source material.
How Policies Interact With Other Features
Section titled “How Policies Interact With Other Features”| Feature | Relationship |
|---|---|
| Brand Voice & Compliance | Defines writing style, banned patterns, answer structure, and rules. |
| Trust Center | Requires explicit operator acknowledgement before chat activation. |
| SafeGuard | Detects published BIQs that violate rules or material. |
| Test Center | Runs policy and abuse cases against the real chat. |
| Compliance Center | Records defended abuse/manipulation attempts. |
Operating Workflow
Section titled “Operating Workflow”- Define policies and Brand Voice rules.
- Generate and review BIQs.
- Run SafeGuard on published BIQs.
- Run Test Center before activating chat.
- Monitor Compliance Center after go-live.
- Add custom Test Center rules for recurring violations.
Best Practices
Section titled “Best Practices”- Keep policies short and enforceable.
- Prefer concrete refusals and escalation rules over vague principles.
- Review policies after real abuse attempts.
- Do not store unnecessary personal data in policy text or violation notes.
- Treat Compliance Center records as security-sensitive operational data.
See also Brand Voice & Compliance, Trust Center, SafeGuard, and Test Center.