ONLY Lang for Compliance Officers
A governance DSL, not a programming language — inspectable, testable, replayable
ONLY Lang for Compliance Officers
A governance DSL, not a programming language
ONLY Lang is not Python. It is not a general-purpose programming language. It is a domain-specific language for declaring governance constraints — and nothing else.
If you are a compliance officer, a risk officer, or a regulator, this is the part of the system you care about. ONLY Lang scripts are the policy. They are inspectable, testable, and replayable. You don't need to read Rust or Python to understand what the gate is doing. You read the script.
What a script looks like
Here is a governance policy for a clinical decision support system:
harmony(1e-12)
assert_bounds(0, 100, 0)
budget_limit(500)
escalate("manual review required for high-value transfer")
residual()
report()
In English:
- The equilibrium tolerance is 1e-12 (extremely strict)
- Field index 0 must be within [0, 100] (e.g., a dosage range)
- The total budget must not exceed 500 (e.g., a cost limit)
- If the gate is uncertain, escalate to a human with the reason "manual review required for high-value transfer"
- Check the residual
- Generate a receipt
That's it. That is the policy. When the gate runs, it evaluates this script against the input and produces a deterministic result: ALLOW, DENY, or ESCALATE.
Why this matters for compliance
Inspectability
A compliance officer can read this script and understand it. They don't need a developer to explain what the gate does. The script is the policy.
Testability
Every script can be tested against known inputs. The DGV test card suite includes 89 tests that verify the gate works correctly. You can run them yourself — they are open source.
Replayability
Every gate decision produces a receipt. The receipt includes the script, the input hash, the result, and the timestamp. An auditor can replay the exact evaluation months or years later. They don't need to trust the system — they can verify it.
Determinism
The gate is deterministic. The same script and the same input always produce the same result. There is no probabilistic guessing. There is no "the model decided." The script decides. The script is the policy.
How this differs from a PDF policy
Most governance policies are documents. A 50-page PDF that says "the system shall not expose PII" or "the system shall escalate high-risk decisions to a human." These documents are necessary, but they are not enforceable. They describe intent. They don't execute.
ONLY Lang scripts execute. A script that says escalate("manual review required") does not describe the intent to escalate — it escalates. Every time. Deterministically. With a receipt.
The compliance officer's workflow
- Review the script. Read the ONLY Lang policy. Confirm it matches your regulatory requirements.
- Approve the script. No script goes live without your sign-off. This is enforced by the deployment process.
- Run the test cards. Run the DGV suite against your configuration. 89 tests. All must pass.
- Monitor the receipts. Every decision is forwarded to your SIEM. You see every ALLOW, DENY, and ESCALATE in real time.
- Replay on audit. When an auditor asks "what happened on this decision?" you show them the receipt. They can replay it.
Try it yourself
Run ONLY Lang scripts in your browser at /try. No signup required. Browse the full command reference at /docs. See all 89 test cards at /dgv/registry.
If you want to see how this works in a production deployment — with HITL escalation, SIEM integration, and identity — see the offer sheet or talk to us.
Published by Only Institute