Repository navigation
logging llm decisions for audit
To audit an LLM decision later you need to know exactly what the model read, what it was asked, what it answered, what rule turned the answer into an action, and which model file and runtime produced it. For a yes/no decision that is a short record: a hash (or a copy) of the state, the questions, each probability, the threshold and the action taken, the model name and file hash, and the timing. With those fields a reviewer can explain the decision, and you can re-run the same request against the same file and compare.
Most LLM logs miss the two fields that matter most for audit: the threshold, which is where the
decision is actually made, and the exact model file, which is what changes silently when
someone updates a dependency. A model name such as jev-latest is an alias, not an identity.
This page is an example record, what each field is for, how to pin the model's identity, how to reproduce a decision, what not to store, and how logs feed review.
One line per decision, as JSON. The answer below is the README's billing example; the hashes are shortened placeholders.
{
"ts": "2026-09-29T10:14:03Z",
"decision_id": "d-7f3a",
"caller": "ticket-router",
"state_sha256": "9c1e...",
"state_tokens": 27,
"questions": {"billing": "Is this a billing problem?"},
"answers": {"billing": 0.94},
"rule": "billing > 0.5",
"action": "queue:billing",
"model": "jevos-v4",
"model_file_sha256": "e41b...",
"jev_release": "jevos-v4",
"inference_ms": 24,
"total_ms": 28
}The timing values in the record are placeholders too; log what the response tells you.
| Field | Why it is there |
|---|---|
| state hash or copy | proves what the model read; the hash lets you match a later complaint to the record without storing the text |
| input token count | tells you whether the text was the one expected (a doubled or truncated input changes it) |
| questions, verbatim | a changed word changes the answer; see why wording changes an LLM's answer |
| probabilities | the evidence; keep all of them, not only the one that drove the action |
| rule and action | the decision itself, in the form code applied it |
| model name and file hash | which model answered, exactly |
| jev release | the rest of what produced the numbers |
| timing | spots slow paths and lets you check latency budgets after the fact |
| caller | which part of the system asked, so one bad caller can be found |
The probabilities are the field people most often throw away after thresholding. Keep them. A decision taken at 0.51 and one taken at 0.99 are different events for a reviewer, and a pile of decisions just above the threshold is the first sign that it is in the wrong place.
GET /health on the jevos server reports, once the model is loaded, the SHA-256 of each model file
and a fingerprint of them all. Read it at startup and attach those values to every record the process
writes, instead of calling it per decision.
Two consequences follow. Any change of model file shows up as a new hash in the log, so a before and after comparison is a
query. And the release file can be checked against the published SHA256SUMS.txt, so the hash
in your log can be tied to a specific public release file.
Every successful jevos response carries a Server-Timing header with inference and total durations.
Log both. The difference between them, and between them and the wall clock of your client, tells
you whether a slow decision was the model, the server or the network. The general method is on
measuring LLM latency: median, p90 and warm-up.
An audit question is often "would the same input give the same answer today?". Keep enough to rebuild the request body: the state (or a way to fetch it again), the questions and the model name. Then run it offline against the same model file:
./jev decide request.json --output replay.json--output writes to a new file and never overwrites one, which suits an audit trail. Comparing
the replay's probabilities with the logged ones shows whether the model still answers the same
way.
Being straight about the limit: we have not published a test of bit-for-bit repeatability across machines or runtime releases, so treat the replay as a check to run and compare, not as a promise. Pin the file and the runtime release, and differences have far fewer places to come from.
- Raw personal data by default. If the state is a customer message, store its hash and a pointer to where the message already lives under its own retention rules. A decision log that duplicates every message becomes a second copy of your most sensitive data.
-
API keys. If the server runs with
JEV_API_KEY, every call except/healthcarries a Bearer token. Do not log request headers wholesale. -
Free-text explanations generated afterwards. jevos generates no text (
output_tokensis always 0), so there is no model rationale to store. An explanation written later by another model is not a record of why this one answered.
Running the model locally keeps the text off third-party servers, but it does not decide who in your company can read the logs. That is access control, and it is covered on a private LLM for text classification.
A log is useful when someone reads it. Three uses repay the effort:
- A review queue. Decisions in the uncertain band go to a person, and the person's verdict is logged next to the model's. The design is on human in the loop AI with a review band.
- A test set. Every reviewed case is a labelled case. After a few weeks you have a set drawn from real traffic to re-check thresholds on.
- Appeals. When someone contests a decision, the record answers what was read, asked and decided, and by which model file.
For decisions about people, the law may require more than a log; the EU case is discussed on GDPR and automated decision-making with an LLM.
What should I log for each LLM decision? State hash, questions, all probabilities, the rule and action, the model name and file hash, jev release, and timing.
Is the model name enough? No. An alias such as jev-latest points at whatever file is
served. Log the fingerprint from /health.
Should I store the input text? Store a hash and a pointer by default. Store the text only when you need replays and your retention rules allow it.
Can I re-run an old decision? Yes, with jev decide on the same request file and model file,
then compare the probabilities.
Why keep probabilities after thresholding? They show how close each decision was, and a cluster near the threshold means the threshold needs a look.
See also: securing a local LLM server with an API key, batch decisions from files with jev decide and gating AI agent tool calls.
- The
/healthfields,Server-Timingheader,jev decidebehaviour,JEV_API_KEY, release files andSHA256SUMS.txt: the jev README and source. - The billing example (0.9, 27 input tokens): the jev README.
- No outside sources are used on this page.
From the notes of jev, a yes/no decision model that runs on a laptop CPU. Its server reports the model's file hashes on /health, the one field most decision logs are missing.
- Ask a local LLM a yes/no question and get P(yes)
- Zero-shot text classification with yes/no questions
- LLM policy decisions: put the rule in the question
- LLM as a judge on a CPU
- Why a small LLM says yes when the answer is no
- Small LLMs and arithmetic in yes/no questions
- Our held-out benchmark said 0.855, new questions said 0.757
- Does an LLM know when a fact is missing?
- jevos vs Jev vs Laya for yes/no decisions
- An open-source alternative to Jev for yes/no decisions
- jevos vs the OpenAI API for yes/no classification
- jevos vs Ollama for yes/no decisions
- jevos vs bart-large-mnli for zero-shot classification
- A yes/no LLM vs a fine-tuned BERT classifier
- jevos vs SetFit: zero-shot vs few-shot classification
- jevos vs Llama Guard for content safety checks
- jev serve vs llama.cpp server for classification
- jevos vs LM Studio: a decision server, not a chat app
- Local vs hosted LLM decisions: latency, cost, privacy
- A yes/no LLM vs a business rules engine
- LLM decisions vs keyword rules and regex
- The fastest AI model for yes/no decisions
- What makes a local LLM fast on a CPU
- Why one forward pass beats generating an answer
- Prefill vs decode: where LLM latency comes from
- Why LLM latency grows with the length of the text
- Why a hosted LLM API cannot answer in 50 ms
- Many questions about one text: why the extra ones are cheap
- CPU or GPU for a small LLM
- Latency budgets: where a 200 ms model fits
- Measuring LLM latency: median, p90 and warm-up
- Q4_K_M vs Q8_0: speed and size for a small model
- Throughput vs latency for a decision server
- What P(yes) means, and what it does not
- LLM calibration explained with yes/no answers
- Expected calibration error (ECE), explained
- Temperature scaling for LLM probabilities
- Platt scaling for a yes/no model
- Reading a reliability diagram
- How to choose a threshold for P(yes)
- Thresholds when a wrong yes costs more than a wrong no
- Human in the loop AI with a review band
- Precision and recall at a P(yes) threshold
- Base rates: why a 0.9 yes can still be wrong often
- Combining yes/no answers with AND, OR and NOT
- Logits, log-odds and P(yes)
- LLM confidence scores: probabilities vs self-reports
- How to write yes/no questions an LLM answers well
- Negation in yes/no questions for an LLM
- One condition per question: splitting compound questions
- Ask whether the text says it at all
- Scores as yes/no thresholds: is it at least high?
- Sending JSON as the text: designing the state
- Why wording changes an LLM's answer, and how to test it
- Mainly about: questions for messages with several topics
- Yes/no questions about tone and emotion
- Asking about intent: what does the writer want?
- Yes/no questions about long documents
- Using an English-only LLM with other languages
- Content moderation with a local LLM
- A Discord moderation bot with a local LLM
- Spam detection with yes/no questions
- Review moderation with a local LLM
- Email triage with a local LLM
- Support ticket routing with yes/no questions
- Urgency detection in customer messages
- Sentiment analysis with yes/no questions
- Intent detection with a local LLM
- Lead qualification with yes/no questions
- Fraud case triage with a local LLM
- Phishing email screening with a local LLM
- Log and alert triage with a local LLM
- Checking text for personal data with yes/no questions
- Prompt injection screening with a small model
- Document classification with a local LLM
- Product categorization with yes/no questions
- Contract clause detection with a local LLM
- Refund request triage with a local LLM
- Detecting cancellation intent in customer messages
- RAG evaluation with yes/no questions
- RAG faithfulness check with a local LLM
- Hallucination detection with a local LLM
- LLM regression tests in CI with yes/no checks
- Rubric design for an LLM judge
- Pairwise comparison with a yes/no judge
- LLM judge bias and how to control it
- Evaluation metrics for yes/no classifiers
- Building a yes/no test set for your own data
- Accuracy by kind of question: why one number hides failures
- Generating test questions with answers computed by code
- Benchmark contamination and truly held-out tests
- An LLM router with yes/no questions
- A model cascade: small model first, large model on doubt
- Semantic routing vs yes/no questions
- Gating AI agent tool calls with yes/no checks
- AI agent guardrails with yes/no questions
- Stop conditions for AI agents
- Logging LLM decisions for audit
- Reducing LLM cost with local yes/no decisions
- Replacing chat LLM calls with yes/no questions
- Structured output vs a probability
- A Python client for local LLM decisions
- Calling a local LLM decision server from JavaScript
- Local LLM yes/no decisions in n8n
- A Slack bot that uses local LLM decisions
- Home Assistant automations with local LLM decisions
- A LangChain tool for local yes/no decisions
- Batch decisions from files with jev decide
- Running LLM yes/no checks in GitHub Actions
- Securing a local LLM server with an API key
- curl examples for a local LLM decision API
- Self-hosted AI for decisions
- A private LLM for text classification
- On-premise LLM for business decisions
- GDPR and automated decision-making with an LLM
- Offline AI for decisions: no network needed
- Edge AI decisions on a CPU
- Run an LLM locally without a GPU
- Small language models explained
- When a small model is enough, and when it is not
- An LLM on a laptop: what it can do in real time
- What is GGUF, for someone deploying a classifier
- GGUF quantization types explained: Q4_K_M, Q8_0 and others
- GGUF vs safetensors
- llama.cpp vs Ollama for a classification service
- llama-cpp-python vs calling llama.cpp through ctypes
- llama.cpp on Windows without compiling
- Running llama.cpp CPU only
- Using llama.cpp prebuilt binaries instead of building