Decision settings
engine, storeInput, storeOutput, timeoutMs, fallbackAction and onEngineError — what each runtime setting of a decision does, its default and its limits — plus the workspace settings.
Each decision has six runtime settings, edited in the Engine & runtime card of the editor (or the Engine node of the visual builder). They are part of the schema, so API clients get a change when you deploy it; the Playground uses the draft's settings right away.
"settings": {
"storeInput": true,
"storeOutput": true,
"timeoutMs": 5000,
"fallbackAction": "escalate",
"onEngineError": "error",
"engine": "laya"
}| Setting | Type | Default | What it does |
|---|---|---|---|
storeInput | boolean | true | Keep the request's state in the execution log. |
storeOutput | boolean | true | Keep result, confidence, weighted levels, composites and the full distributions in the execution log. |
timeoutMs | integer, 500–30,000 | 5000 | The engine deadline for one call of this decision, retries included, in milliseconds. |
fallbackAction | continue, block, escalate, fallback | escalate | The action when a choice answers other or a question is below its minConfidence and no policy matched — and, with onEngineError: "fallback", when the engine fails. |
onEngineError | error, fallback | error | What the API answers when the engine fails: the error, or a 200 with the fallback action. |
engine | jev, laya | absent | The engine that runs this decision. Absent = the workspace's default engine. See Engines and BYOK. |
engine
Leave it out to follow the workspace's default engine (Settings → Engine) — changing the default then moves every such decision at once. Set it to pin one decision to an engine: for example keep the workspace on Jev and run a multilingual triage decision on Laya. In the editor: Engine & runtime → Engine.
The engine must be set up in Settings → Engine — for Laya, a Laya server — otherwise runs answer 424 ENGINE_NOT_CONFIGURED. Re-test thresholds such as minConfidence in the Playground when you switch engines: each model has its own confidence profile.
storeInput and storeOutput
These settings only affect what is logged; the API response is always complete.
- With
storeInputoff, executions show Not stored (storeInput is off) instead of the state, and the run can't be replayed in the Playground. Invalid states are not stored either. - With
storeOutputoff, executions keep the status, action, action reason, latency, model, tokens and estimated cost, but not the answers, confidence, weighted levels, composites or distributions.
Turn them off for decisions that receive personal or sensitive data. See Security and data.
When a request carries an Idempotency-Key, its response — answers included — is kept for 24 hours so a retry can be replayed, whatever storeOutput says. See Idempotency.
timeoutMs
The deadline for the engine, from 500 ms to 30 s — 5 seconds by default. It covers the whole engine call, retries included:
- Dcision makes up to 2 retries on network errors,
429,503,529and other5xxanswers from the provider, waiting 200 ms and then 400 ms — or the provider'sRetry-Afterwhen it sends one and it fits in the deadline. - A timeout isn't retried, and neither is a
4xxother than429. - On Dcision's shared engine key, bursts wait for a free slot inside the same deadline instead of failing at once.
A call that runs out of time fails with 504 ENGINE_TIMEOUT — or answers with the fallback action when onEngineError is fallback. Raise timeoutMs for large states or many questions; lower it on latency-critical paths that have a fallback. Give your own HTTP client a timeout a few seconds longer than timeoutMs.
fallbackAction
The action applied when no policy matched and either a choice question answered the reserved other option or a question's confidence fell below its minConfidence. The default, escalate, sends uncertain cases to a person; continue effectively ignores uncertainty. See Policies and actions.
The fallback action is also what onEngineError: "fallback" answers when the engine fails.
onEngineError
What happens when the engine fails — a timeout, an overloaded or unreachable provider, a rejected key, an answer outside the contract — after the retries:
| Value | The API answers |
|---|---|
error (default) | The error, such as 504 ENGINE_TIMEOUT or 503 ENGINE_UNAVAILABLE. Your code decides what it means. |
fallback | 200 OK with action = the decision's fallbackAction, action_reason = { "type": "engine_error", "code": "<engine error code>" }, an empty result and confidence, and zero tokens and cost. |
{
"decision_id": "dec_3fKq9ZtW1mXcV7bN2pLa",
"execution_id": "exec_Vn4Kp8Wd2Lq6Tz1Xc9Bs",
"schema": "lead-qualification",
"version": 3,
"result": {},
"confidence": {},
"action": "escalate",
"action_reason": { "type": "engine_error", "code": "ENGINE_TIMEOUT" },
"metrics": {
"latency_ms": 5004,
"engine": "jev",
"model": "jev-1.13.0",
"estimated_cost_usd": 0,
"input_tokens": 0,
"output_tokens": 0
}
}- These answers are not billed and not stored for idempotency: retrying with the same
Idempotency-Keyreaches the engine again. - The run is recorded as an execution with status Error and the engine's error code.
- It covers engine failures only (the
ENGINE_*codes exceptENGINE_NOT_CONFIGURED). Invalid states, quota, rate limits and a missing engine key still answer with their errors.
Choose fallback for paths that must always answer — a chat or a voice assistant, a checkout — and pick a fallbackAction that is safe without answers, usually escalate. In the editor: Engine & runtime → If the engine fails → Answer with the fallback action.
Workspace settings
Settings in the app holds what applies to every decision of the workspace. Everyone in the workspace can open it; Admins and the Owner change it, and the Danger zone belongs to the Owner alone — see Team, roles and account.
| Setting | Who changes it | Description |
|---|---|---|
| Name | Admins and the Owner | The workspace name, 2 to 80 characters. The workspace slug is fixed. |
| Execution log retention | Admins and the Owner | 7, 14, 30, 90, 180 or 365 days. Your plan caps it: logs are kept for the shorter of this value and the plan's retention — see Executions and usage. |
| Engine | Admins and the Owner | The default engine — Jev or Laya — and how each one is called: Dcision's key or server, or your own provider key or Laya server, with the model. See Engines and BYOK. Applies to new runs immediately, for every decision that doesn't pick its own engine. |
| Organization | Admins and the Owner | Legal name, tax ID, billing e-mail, country, address and website — printed on invoices. |
| Members | Admins for Members and Viewers; the Owner for Admins | Who is in the workspace and their role — Owner, Admin, Member or Viewer — plus invitations. See Team, roles and account. |
| Destinations | Admins and the Owner | The signing secret of deliveries and the workspace secrets that destinations use. |
| Danger zone | The Owner | Delete the workspace. |
Versions and deploy
Drafts, immutable versions, deploys, slugs, disabling, duplicating and deleting decisions — and what your API clients see at each step.
Templates
The nine built-in templates — what each one decides, its questions, composites and policies, the patterns it demonstrates — and how to start a decision from one.