Skip to content

24. Compliance Center & Policies

Compliance Center and Policies are the operator-facing controls for abuse records and policy configuration. They complement Trust Center, SafeGuard, and Test Center.

The Compliance Center logs abuse or manipulation attempts against the Chat Advisor. Harmless off-topic questions should not appear there.

Violation categories include:

  • direct prompt injection,
  • indirect injection or RAG poisoning,
  • system-prompt extraction,
  • data-leak attempt,
  • hallucination provocation,
  • jailbreak or roleplay,
  • scope overreach,
  • lead or conversion abuse.

Each record can show:

  • input,
  • violation type,
  • timestamp,
  • IP address,
  • whether the attempt was defended and logged.

Use Compliance Center to understand attempted abuse and to decide whether prompts, policies, material, or Test Center rules need tightening.

Policies are organization rules that guide what Klariton may answer, refuse, or escalate. They are related to Brand Voice but focus more on allowed behavior and compliance boundaries.

Typical policies include:

  • do not make legal commitments,
  • do not guarantee prices outside checkout,
  • do not invent discounts,
  • do not expose internal prompts or system instructions,
  • do not process personal data beyond the intended workflow,
  • escalate sensitive questions to support,
  • answer product facts only from source material.
FeatureRelationship
Brand Voice & ComplianceDefines writing style, banned patterns, answer structure, and rules.
Trust CenterRequires explicit operator acknowledgement before chat activation.
SafeGuardDetects published BIQs that violate rules or material.
Test CenterRuns policy and abuse cases against the real chat.
Compliance CenterRecords defended abuse/manipulation attempts.
  1. Define policies and Brand Voice rules.
  2. Generate and review BIQs.
  3. Run SafeGuard on published BIQs.
  4. Run Test Center before activating chat.
  5. Monitor Compliance Center after go-live.
  6. Add custom Test Center rules for recurring violations.
  • Keep policies short and enforceable.
  • Prefer concrete refusals and escalation rules over vague principles.
  • Review policies after real abuse attempts.
  • Do not store unnecessary personal data in policy text or violation notes.
  • Treat Compliance Center records as security-sensitive operational data.

See also Brand Voice & Compliance, Trust Center, SafeGuard, and Test Center.