Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Publications
article

ONLY Lang for Compliance Officers

A governance DSL, not a programming language — inspectable, testable, replayable

Grigori Korotkikh 2026-09-13 7 min
ONLY LangComplianceGovernanceDSL
Only Institute — ONLY Lang for Compliance Officers

ONLY Lang for Compliance Officers

A governance DSL, not a programming language

ONLY Lang is not Python. It is not a general-purpose programming language. It is a domain-specific language for declaring governance constraints — and nothing else.

If you are a compliance officer, a risk officer, or a regulator, this is the part of the system you care about. ONLY Lang scripts are the policy. They are inspectable, testable, and replayable. You don't need to read Rust or Python to understand what the gate is doing. You read the script.

What a script looks like

Here is a governance policy for a clinical decision support system:

harmony(1e-12)
assert_bounds(0, 100, 0)
budget_limit(500)
escalate("manual review required for high-value transfer")
residual()
report()

In English:

  • The equilibrium tolerance is 1e-12 (extremely strict)
  • Field index 0 must be within [0, 100] (e.g., a dosage range)
  • The total budget must not exceed 500 (e.g., a cost limit)
  • If the gate is uncertain, escalate to a human with the reason "manual review required for high-value transfer"
  • Check the residual
  • Generate a receipt

That's it. That is the policy. When the gate runs, it evaluates this script against the input and produces a deterministic result: ALLOW, DENY, or ESCALATE.

Why this matters for compliance

Inspectability

A compliance officer can read this script and understand it. They don't need a developer to explain what the gate does. The script is the policy.

Testability

Every script can be tested against known inputs. The DGV test card suite includes 89 tests that verify the gate works correctly. You can run them yourself — they are open source.

Replayability

Every gate decision produces a receipt. The receipt includes the script, the input hash, the result, and the timestamp. An auditor can replay the exact evaluation months or years later. They don't need to trust the system — they can verify it.

Determinism

The gate is deterministic. The same script and the same input always produce the same result. There is no probabilistic guessing. There is no "the model decided." The script decides. The script is the policy.

How this differs from a PDF policy

Most governance policies are documents. A 50-page PDF that says "the system shall not expose PII" or "the system shall escalate high-risk decisions to a human." These documents are necessary, but they are not enforceable. They describe intent. They don't execute.

ONLY Lang scripts execute. A script that says escalate("manual review required") does not describe the intent to escalate — it escalates. Every time. Deterministically. With a receipt.

The compliance officer's workflow

  1. Review the script. Read the ONLY Lang policy. Confirm it matches your regulatory requirements.
  2. Approve the script. No script goes live without your sign-off. This is enforced by the deployment process.
  3. Run the test cards. Run the DGV suite against your configuration. 89 tests. All must pass.
  4. Monitor the receipts. Every decision is forwarded to your SIEM. You see every ALLOW, DENY, and ESCALATE in real time.
  5. Replay on audit. When an auditor asks "what happened on this decision?" you show them the receipt. They can replay it.

Try it yourself

Run ONLY Lang scripts in your browser at /try. No signup required. Browse the full command reference at /docs. See all 89 test cards at /dgv/registry.

If you want to see how this works in a production deployment — with HITL escalation, SIEM integration, and identity — see the offer sheet or talk to us.


Back to Publications

Published by Only Institute