Policy
bro command reference for policy.
See Init and config for shared conventions and environment variables.
Routing policies are the artifact the self-improving loop learns into: init scaffolds policy-lock.yaml and binds it to a preset, live traffic teaches the adequacy ledger, and evolve --apply folds proven downgrades back into the file. The walkthrough, table, and ledger semantics are in Routing policy.
bro policy create + bro key sign are a different surface — per-virtual-key access control (allowed models, budgets, rate limits), not routing. See access-control policies.
bro policy
Policy management
Usage: bro policy <COMMAND>
bro policy create
Write a starter access-control policy file to the policy dir
Usage: bro policy create [OPTIONS] <ID>
| Argument | Description |
|---|---|
<ID> | Policy id (becomes the file stem and the id: field) |
| Flag | Description |
|---|---|
--dir <DIR> | Policy directory. Default matches the assembly default [default: ./policies] |
bro policy init
Create a routing policy lock and bind it to a preset
Usage: bro policy init [OPTIONS] --preset <PRESET> --economy <ECONOMY> <NAME>
| Argument | Description |
|---|---|
<NAME> | Policy name written under policies: |
| Flag | Description |
|---|---|
--preset <PRESET> | Preset users select as @preset or @preset:variant |
--strong <STRONG> | Strong base model. Inferred from an existing preset when omitted |
--strong-effort <STRONG_EFFORT> | Exact reasoning effort owned by the strong target |
--economy <ECONOMY> | Economy model explored as a replacement |
--economy-effort <ECONOMY_EFFORT> | Exact reasoning effort owned by the economy target |
-c, --config <CONFIG> | Path to bitrouter.yaml |
bro policy init coding --preset coding \
--economy moonshotai/kimi-k2.7-codeWrites policy-lock.yaml (strong/economy tiers, adequacy pre-seeded) and edits bitrouter.yaml comment-preservingly to bind the preset with writeback: locked.
bro policy check
Parse and cross-validate bitrouter.yaml and its policy lock
Usage: bro policy check [OPTIONS]
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro policy verify
Verify the lock's compiled evidence root against the local ledger
Usage: bro policy verify [OPTIONS]
| Flag | Description |
|---|---|
--evidence | |
-c, --config <CONFIG> |
bro policy status
Show policy path, digest, runtime mode, and preset bindings
Usage: bro policy status [OPTIONS]
| Flag | Description |
|---|---|
--view <VIEW> | Read disk locally by default; a remote context defaults to active [possible values: active, disk] |
-c, --config <CONFIG> | |
--socket <SOCKET> | Explicit local control socket for an active policy read |
bro policy show
Show one named policy after validation
Usage: bro policy show [OPTIONS] <NAME>
| Argument | Description |
|---|---|
<NAME> |
| Flag | Description |
|---|---|
--view <VIEW> | Read disk locally by default; a remote context defaults to active [possible values: active, disk] |
-c, --config <CONFIG> | |
--socket <SOCKET> | Explicit local control socket for an active policy read |
bro policy reload
Hot-reload the policy lock through the daemon control socket
Usage: bro policy reload [OPTIONS]
| Flag | Description |
|---|---|
-c, --config <CONFIG> | |
--socket <SOCKET> |
Hot-reloads the daemon's policy snapshot. An invalid lock is rejected and the daemon keeps its last-known-good.
bro policy compile
Compile a deterministic v3 candidate without changing the active lock
Usage: bro policy compile [OPTIONS] --output <FILE>
| Flag | Description |
|---|---|
--output <FILE> | Candidate output path |
--snapshot-time <UNIX_MS> | Frozen evidence snapshot time in Unix milliseconds |
--eval-snapshot <SHA256> | Immutable admitted-evidence root from eval snapshot freeze |
-c, --config <CONFIG> |
bro policy diff
Compare explicit routes in two policy lock artifacts
Usage: bro policy diff <ACTIVE> <CANDIDATE>
| Argument | Description |
|---|---|
<ACTIVE> | |
<CANDIDATE> |
bro policy publish
Publish one already-compiled candidate after lineage validation
Usage: bro policy publish [OPTIONS] <CANDIDATE>
| Argument | Description |
|---|---|
<CANDIDATE> |
| Flag | Description |
|---|---|
-c, --config <CONFIG> | |
--socket <SOCKET> |
bro policy evolve
Project qualified database evidence into a deterministic policy lock
Usage: bro policy evolve [OPTIONS]
| Flag | Description |
|---|---|
--apply | Publish the candidate. Without this flag, print a dry-run report |
--output <FILE> | Export the candidate without changing the active policy lock |
-c, --config <CONFIG> |
bro policy evolve # dry-run candidate projection
bro policy unlock
bro policy evolve --apply # atomically republish policy-lock.yaml
bro policy lockOnly adds qualified routes — never overwrites or removes yours — and refuses to publish while writeback: locked.
bro policy rollback
Restore an exact lock snapshot from local promotion history
Usage: bro policy rollback [OPTIONS] <DIGEST>
| Argument | Description |
|---|---|
<DIGEST> |
| Flag | Description |
|---|---|
-c, --config <CONFIG> | |
--socket <SOCKET> |
bro eval
Evaluator-neutral evidence exchange
Usage: bro eval <COMMAND>
bro eval subject
Create, inspect, and list eval subjects
Usage: bro eval subject <COMMAND>
bro eval subject seal
Calculate the canonical evidence digest and write a validated JSON subject
Usage: bro eval subject seal --output <FILE> <DRAFT>
| Argument | Description |
|---|---|
<DRAFT> | Draft JSON or YAML subject with redacted evidence items |
| Flag | Description |
|---|---|
--output <FILE> | Destination for the deterministic sealed JSON subject |
bro eval subject put
Insert an immutable subject from JSON or YAML
Usage: bro eval subject put [OPTIONS] <FILE>
| Argument | Description |
|---|---|
<FILE> |
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro eval subject get
Get one subject by eval id
Usage: bro eval subject get [OPTIONS] <EVAL_ID>
| Argument | Description |
|---|---|
<EVAL_ID> |
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro eval subject list
List subjects
Usage: bro eval subject list [OPTIONS]
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro eval result
Submit an evaluator result through authority admission
Usage: bro eval result <COMMAND>
bro eval result submit
Submit an immutable result from JSON or YAML as the local operator
Usage: bro eval result submit [OPTIONS] <FILE>
| Argument | Description |
|---|---|
<FILE> |
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro eval snapshot
Freeze or inspect an immutable admitted-evidence snapshot
Usage: bro eval snapshot <COMMAND>
bro eval snapshot freeze
Freeze all currently admitted results into a content-addressed manifest
Usage: bro eval snapshot freeze [OPTIONS]
| Flag | Description |
|---|---|
--at <AT> | |
-c, --config <CONFIG> |
bro eval snapshot get
Get a frozen manifest by evidence root
Usage: bro eval snapshot get [OPTIONS] <EVIDENCE_ROOT>
| Argument | Description |
|---|---|
<EVIDENCE_ROOT> |
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro eval status
Summarize local exchange state
Usage: bro eval status [OPTIONS]
| Flag | Description |
|---|---|
-c, --config <CONFIG> |
bro optimize
Advance or inspect history-driven routing optimization
Usage: bro optimize <COMMAND>
bro optimize run
Perform one deterministic controller transition from admitted Eval history
Usage: bro optimize run [OPTIONS]
| Flag | Description |
|---|---|
--policy <POLICY> | [default: auto] |
--candidate-tier <CANDIDATE_TIER> | Challenger tier; defaults to the policy's adequacy explore tier |
--exploration-ppm <EXPLORATION_PPM> | [default: 100000] |
--minimum-tasks <MINIMUM_TASKS> | [default: 3] |
--maximum-tasks <MAXIMUM_TASKS> | [default: 20] |
--minimum-pass-rate-ppm <MINIMUM_PASS_RATE_PPM> | [default: 900000] |
--evaluator-config-digest <EVALUATOR_CONFIG_DIGEST> | |
-c, --config <CONFIG> | [default: bitrouter.yaml] |
--socket <SOCKET> |
bro optimize status
Inspect the current controller state without changing files or the database
Usage: bro optimize status [OPTIONS]
| Flag | Description |
|---|---|
--policy <POLICY> | [default: auto] |
-c, --config <CONFIG> | [default: bitrouter.yaml] |
bro trajectory
Inspect, replay, and retain durable trajectory history in the local database
Usage: bro trajectory [OPTIONS] <COMMAND>
| Flag | Description |
|---|---|
-c, --config <CONFIG> | Path to bitrouter.yaml. Uses the standard config resolution chain when omitted |
bro trajectory inspect
Inspect one episode's structural health, route intents, and event digests
Usage: bro trajectory inspect [OPTIONS] <EPISODE_ID>
| Argument | Description |
|---|---|
<EPISODE_ID> | Globally unique trajectory episode id |
| Flag | Description |
|---|---|
-c, --config <CONFIG> | Path to bitrouter.yaml. Uses the standard config resolution chain when omitted |
bro trajectory replay
Verify one episode and compare persisted live checkpoint evidence with replay
Usage: bro trajectory replay [OPTIONS] <EPISODE_ID>
| Argument | Description |
|---|---|
<EPISODE_ID> | Globally unique trajectory episode id |
| Flag | Description |
|---|---|
-c, --config <CONFIG> | Path to bitrouter.yaml. Uses the standard config resolution chain when omitted |
bro trajectory prune
Prune delivered outbox rows and retention-expired terminal episodes
Usage: bro trajectory prune [OPTIONS] --before <BEFORE>
| Flag | Description |
|---|---|
--before <BEFORE> | Exclusive RFC3339 cutoff |
-c, --config <CONFIG> | Path to bitrouter.yaml. Uses the standard config resolution chain when omitted |
--dry-run | Report exact eligible counts without mutating the database |
How is this guide?