Your policy tree.
Jev reviews each agent step.

Maintain the rules. Route each request and proposed action. Review safety and category at the leaf before the harness proceeds.

93.20%Full-path routing accuracy

1,000 held-out routes · no confidence filtering

91.78%Overall safety accuracy

73,415 / 79,987 labeled safety records

58.0 msMean native forward latency

147,643 records · excludes full routing + review

1

A policy tree you can change.

Content, cyber, privacy and compliance share one tree. Each leaf holds the applicable taxonomy and review rules. Change the tree to fit your agent.

The maintained tree

cyber.authorization

Website preview: edits stay in this browser. Use /safety-policy in Hermes to change its live policy.

2

Route to a leaf. Review safety and category.

Jev chooses a branch at each level using the request and its audit context. At the selected leaf, it predicts safety and the applicable categories. The harness combines these outputs with authorization rules.

User request

What is gravity?

Safety

safe

Category

No applicable risk category

Harness decision

ALLOW

The request reaches the assistant model.

Illustrated workflow; this page does not call the reviewer.

Before the assistant model

If a user request is blocked, the assistant model is not called.

Before each tool

If a proposed action is blocked, the tool does not execute. The interception appears in the conversation.

See the tree and review flow in Hermes.

English narration · English and Chinese captions. The opening animates an actual Jev action-review trace. The following Hermes + DeepSeek session explains each input and highlights Jev interceptions in red.

Demo and recording details ↗
3

A small classifier with typed outputs.

Qwen3.5-2B with rank-8 LoRA and classification heads. Routing and leaf review use structured probabilities rather than generated explanations.

Request + context + candidates

Child branches for routing; leaf taxonomy for review.

↓

Qwen3.5-2B + LoRA

Last non-padding hidden state

↓

Safety

Two-class linear head

safe / unsafe

Category / Routing

Candidate embedding similarity

softmax / sigmoid

Score

Scalar + ordered thresholds

Ordinal severity
2Bbackbone parameters
16Ktext context
93.2%full-path routing · 1,000 cases

Safety and category across four domains

147,643 native task records across 109 benchmark views. Safety accuracy and category micro-F1 use records with the corresponding supervision.

DomainTask casesSafety accuracyCategory micro-F1
All 109 benchmark results
BenchmarkCasesSafety accuracyCategory F1Median forward
Evaluation protocol and known limits

Selected v3.2 continuation checkpoint at update 1,508 after one epoch; a validation plateau was not established. Native tests retain original v3.1 candidates and gold labels. Full-path routing starts at root without gold intermediate nodes, with caller audit context supplied.

Controlled action-state replay caught 49/52 malicious proposals and allowed 87/97 benign proposals, including one API error among interruptions. No attacker action was executed; this is not end-to-end attack success or a production error estimate.

Quoted injection analysis can still be incorrectly blocked. Some expanded categories have no positive training examples. Ordinal severity exact accuracy is 15.28% on 1,466 cases. Editing the tree does not retrain the model. Keep native permissions and explicit scope checks.

Machine-readable evidence ↗

Use it with Hermes

Copy and run on macOS or Linux. This installer connects to our hosted Jev v3.2 reviewer over HTTPS; no local GPU is needed. It installs or updates the supplement, preserves your policy, and checks the connection.

curl -fsSL https://huggingface.co/hubin/jev-guard-v3.2-2b/resolve/main/downloads/install-hermes-jev.txt -o /tmp/install-hermes-jev.sh
bash /tmp/install-hermes-jev.sh --endpoint https://approaches-lemon-antique-garden.trycloudflare.com
# Then start the guarded conversation:
jev-hermes

The assistant still needs its provider credentials. Configure your assistant provider with hermes setup; existing credentials are preserved.

Use your own reviewer server

The same installer can prompt for your reviewer URL. No SSH host is assumed in this mode. The model is downloadable on Hugging Face; deploy its reviewer server before connecting Hermes.

bash /tmp/install-hermes-jev.sh