What should be blocked isn't decided by the model — it's decided by the company deploying it, its industry, and its internal policy, and it's different for every product. A hospital's over-refusal threshold is a bank's bare minimum. A phrase that's an attack inside a customer-support bot is a red team's everyday vocabulary. No generalist safety model can encode this, and no vendor can hand it to you pre-configured. Geodesia doesn't sell a fixed line — it sells a system that learns your line from your traffic, under human supervision, inside your perimeter.
Every correction your reviewers approve moves through the system on a horizon that matches how much trust it has earned — from an instant, reversible threshold change to a deliberate, human-gated change to the model's weights. Nothing moves without a human flagging it first and a curator approving it.
You move a threshold through Policy Lens, and it's live from the very next request — but only after Policy Lens simulates its exact effect on your real, already-logged traffic first, so the move is a decision, not a guess. More on Policy Lens →
An approved correction enters an episodic memory that is consulted at scoring time. The corrected pattern is recalled the next time something similar appears — without retraining anything, and without touching the model's weights.
The approved corpus of corrections enters the model weights only when a human decides it should — a separate, deliberate, gated step, never an automatic consequence of accumulating incidents.
The detector's geometry is validated out-of-distribution, and that validation is itself the product you're buying. Patching the model for a single embarrassing case means trading a measured general capability for a local fix — and discovering the damage months later, on traffic you can't reproduce. That is a trade Geodesia will not make silently on your behalf.
So customer-specific incidents are memorised in a store that sits alongside the model and never touches its weights, until a deliberate, separate step promotes them. The immediate and fast horizons give you speed without risking the geometry; the structural horizon gives you permanence, but only when a human — not an accumulation of traffic — decides it belongs there.
This is the part a CISO reads first. Each line is a boundary we hold, not an aspiration.
The line is decided by the vendor, calibrated on traffic you can't see, and shipped as a default. Moving it means opening a support ticket and waiting for someone else's release cycle.
The line is calibrated on your own logged traffic, moved by your own reviewers, simulated before it ships, and promoted into the weights only when your team decides. You own the policy, not just the interface to it.