Decision settings

engine, storeInput, storeOutput, timeoutMs, fallbackAction and onEngineError — what each runtime setting of a decision does, its default and its limits — plus the workspace settings.

Each decision has six runtime settings, edited in the Engine & runtime card of the editor (or the Engine node of the visual builder). They are part of the schema, so API clients get a change when you deploy it; the Playground uses the draft's settings right away.

"settings": {
  "storeInput": true,
  "storeOutput": true,
  "timeoutMs": 5000,
  "fallbackAction": "escalate",
  "onEngineError": "error",
  "engine": "laya"
}
SettingTypeDefaultWhat it does
storeInputbooleantrueKeep the request's state in the execution log.
storeOutputbooleantrueKeep result, confidence, weighted levels, composites and the full distributions in the execution log.
timeoutMsinteger, 500–30,0005000The engine deadline for one call of this decision, retries included, in milliseconds.
fallbackActioncontinue, block, escalate, fallbackescalateThe action when a choice answers other or a question is below its minConfidence and no policy matched — and, with onEngineError: "fallback", when the engine fails.
onEngineErrorerror, fallbackerrorWhat the API answers when the engine fails: the error, or a 200 with the fallback action.
enginejev, layaabsentThe engine that runs this decision. Absent = the workspace's default engine. See Engines and BYOK.

engine

Leave it out to follow the workspace's default engine (Settings → Engine) — changing the default then moves every such decision at once. Set it to pin one decision to an engine: for example keep the workspace on Jev and run a multilingual triage decision on Laya. In the editor: Engine & runtime → Engine.

The engine must be set up in Settings → Engine — for Laya, a Laya server — otherwise runs answer 424 ENGINE_NOT_CONFIGURED. Re-test thresholds such as minConfidence in the Playground when you switch engines: each model has its own confidence profile.

storeInput and storeOutput

These settings only affect what is logged; the API response is always complete.

  • With storeInput off, executions show Not stored (storeInput is off) instead of the state, and the run can't be replayed in the Playground. Invalid states are not stored either.
  • With storeOutput off, executions keep the status, action, action reason, latency, model, tokens and estimated cost, but not the answers, confidence, weighted levels, composites or distributions.

Turn them off for decisions that receive personal or sensitive data. See Security and data.

When a request carries an Idempotency-Key, its response — answers included — is kept for 24 hours so a retry can be replayed, whatever storeOutput says. See Idempotency.

timeoutMs

The deadline for the engine, from 500 ms to 30 s — 5 seconds by default. It covers the whole engine call, retries included:

  • Dcision makes up to 2 retries on network errors, 429, 503, 529 and other 5xx answers from the provider, waiting 200 ms and then 400 ms — or the provider's Retry-After when it sends one and it fits in the deadline.
  • A timeout isn't retried, and neither is a 4xx other than 429.
  • On Dcision's shared engine key, bursts wait for a free slot inside the same deadline instead of failing at once.

A call that runs out of time fails with 504 ENGINE_TIMEOUT — or answers with the fallback action when onEngineError is fallback. Raise timeoutMs for large states or many questions; lower it on latency-critical paths that have a fallback. Give your own HTTP client a timeout a few seconds longer than timeoutMs.

fallbackAction

The action applied when no policy matched and either a choice question answered the reserved other option or a question's confidence fell below its minConfidence. The default, escalate, sends uncertain cases to a person; continue effectively ignores uncertainty. See Policies and actions.

The fallback action is also what onEngineError: "fallback" answers when the engine fails.

onEngineError

What happens when the engine fails — a timeout, an overloaded or unreachable provider, a rejected key, an answer outside the contract — after the retries:

ValueThe API answers
error (default)The error, such as 504 ENGINE_TIMEOUT or 503 ENGINE_UNAVAILABLE. Your code decides what it means.
fallback200 OK with action = the decision's fallbackAction, action_reason = { "type": "engine_error", "code": "<engine error code>" }, an empty result and confidence, and zero tokens and cost.
200 OK with onEngineError: fallback
{
  "decision_id": "dec_3fKq9ZtW1mXcV7bN2pLa",
  "execution_id": "exec_Vn4Kp8Wd2Lq6Tz1Xc9Bs",
  "schema": "lead-qualification",
  "version": 3,
  "result": {},
  "confidence": {},
  "action": "escalate",
  "action_reason": { "type": "engine_error", "code": "ENGINE_TIMEOUT" },
  "metrics": {
    "latency_ms": 5004,
    "engine": "jev",
    "model": "jev-1.13.0",
    "estimated_cost_usd": 0,
    "input_tokens": 0,
    "output_tokens": 0
  }
}
  • These answers are not billed and not stored for idempotency: retrying with the same Idempotency-Key reaches the engine again.
  • The run is recorded as an execution with status Error and the engine's error code.
  • It covers engine failures only (the ENGINE_* codes except ENGINE_NOT_CONFIGURED). Invalid states, quota, rate limits and a missing engine key still answer with their errors.

Choose fallback for paths that must always answer — a chat or a voice assistant, a checkout — and pick a fallbackAction that is safe without answers, usually escalate. In the editor: Engine & runtime → If the engine fails → Answer with the fallback action.

Workspace settings

Settings in the app holds what applies to every decision of the workspace. Everyone in the workspace can open it; Admins and the Owner change it, and the Danger zone belongs to the Owner alone — see Team, roles and account.

SettingWho changes itDescription
NameAdmins and the OwnerThe workspace name, 2 to 80 characters. The workspace slug is fixed.
Execution log retentionAdmins and the Owner7, 14, 30, 90, 180 or 365 days. Your plan caps it: logs are kept for the shorter of this value and the plan's retention — see Executions and usage.
EngineAdmins and the OwnerThe default engine — Jev or Laya — and how each one is called: Dcision's key or server, or your own provider key or Laya server, with the model. See Engines and BYOK. Applies to new runs immediately, for every decision that doesn't pick its own engine.
OrganizationAdmins and the OwnerLegal name, tax ID, billing e-mail, country, address and website — printed on invoices.
MembersAdmins for Members and Viewers; the Owner for AdminsWho is in the workspace and their role — Owner, Admin, Member or Viewer — plus invitations. See Team, roles and account.
DestinationsAdmins and the OwnerThe signing secret of deliveries and the workspace secrets that destinations use.
Danger zoneThe OwnerDelete the workspace.

On this page