Governance, Safety and Evaluation
Civitas is engineered to expose uncertainty and preserve human accountability rather than manufacture artificial confidence.
Evidence State Categorization
The platform tracks four distinct categories of information across all workflows and user interfaces:
- Observed: Directly confirmed by media analysis or sensor data.
- Reported: Asserted by citizens in their raw text submission.
- Retrieved: Extracted from verified municipal policy playbooks and PostGIS databases.
- Inferred: Recommended by agentic models and subject to human review.
Policy Grounding & Adversarial Guardrails
Every policy-dependent claim in a work order or routing decision must cite a valid retrieved municipal playbook (e.g., PLAY-WATER-01). If no grounding playbook exists, the workflow records INSUFFICIENT_KNOWLEDGE and requests manual human supervisor review. Adversarial hallucination guardrails reject fabricated response SLAs or unauthorized repair commitments.
Agents are strictly prohibited from inventing municipal jurisdictions, response SLAs, or repair commitments.
Contractor Resolution Anti-Fraud (64-bit dHash)
To prevent contractor payment fraud (such as uploading stock repair photos or recycling past resolution photos), Civitas hashes resolution media using 64-bit perceptual difference hashing (dHash) with a Hamming distance threshold (<= 5 bits). Duplicate attempts are flagged immediately for municipal audit.
Differential Privacy Spatial Perturbation (±25m)
Public transparency feeds and open data exports (/api/v1/public/incidents.geojson) apply differential privacy spatial perturbation. Bounded Gaussian jitter (±25m) and automated regex scrubbing redact residential street numbers and PII while preserving regional geographic trends for urban planners.
Supervisor Review Controls
Review actions are deliberately constrained to five canonical operations: Approve, Edit Work Order, Reroute Department, Reject, and Request Additional Evidence. Rejections cannot create an active work order.