Expanso + Jev

Deterministic pipelines. Judgment where it counts.

Expanso does the part of a pipeline that must come out the same every time: shape, fingerprint, count, route. Jev does the part no rule can write: is this actionable, how severe, whose problem. Ten real pipelines show exactly where one hands off to the other.

SourcePOST /logs
Expanso nodeone pipeline, 10 steps, deterministic
  1. Receive
  2. Wait
  3. Fingerprint
  4. Count
  5. Bypass
  6. Ask Jev
  7. Gate
  8. Log
  9. Record
  10. Route
Jev judgment
  • actionable
  • severity
  • team
  • recurrence_concern
  • page
  • notify
  • review
  • archive
One record through the log triage pipeline, for a line the bypass did not clear. Every step inside the Expanso node is deterministic in what it does to the record: it applies the same fixed rules every time, with no model involved, including the bypass that archives known-routine lines with no model call. The Wait step's timing is jittered: the file sleeps 2000 + random_int(max: 2000) ms. On a pass where Jev answers, the record leaves once, at a right angle, for Jev's judgment, and comes back carrying the answers. A held record is sent to Jev again on each retry. Which decision each pass lands in cycles in order here; in the pipeline the gate picks it from Jev's answers.

Two halves of one pipeline

Most of a pipeline should never surprise you. One step in it needs judgment. Putting both in the same tool makes the predictable part unpredictable. These examples keep them apart, and the seam between them is a single HTTP call you can read.

The substrate

Expanso, deterministic

Receives the record, normalizes it, fingerprints it, counts how often it has been seen, applies fixed thresholds, and writes it to the right place. The same fixed rules every time, with no model involved. It runs on nodes you control, next to where the data is created.

  • shape
  • fingerprint
  • count
  • gate
  • route

The judgment layer

Jev, judgment

Answers typed questions about one record at a time. It returns values a pipeline can compare against a number, so its judgment arrives in a form the deterministic half can act on.

  • actionable
  • severity
  • team
  • recurrence concern

How the handoff works

The same four moves appear in all ten pipelines.

  1. Shape the record

    Expanso

    Parse it, stamp it, and add the context a judgment needs. Log triage adds a fingerprint and an occurrence count, then archives known-routine lines itself so they never reach the model. Sensor triage attaches the asset's baseline. None of this involves a model.

  2. Ask typed questions

    Jev

    The pipeline posts the record with a set of questions. Each has a type that fixes the form of the answer:

    • noul A yes-or-no question answered as a number from 0 to 1.
    • choice One of the named options, with a confidence.
    • score A position on a five-step scale, 0 to 4, each step described in the request.
  3. Gate on the answers

    Expanso

    Fixed thresholds, checked in order, turn Jev's answers into one route. The ticket router pages on-call when $urgent >= 0.9 and sends a ticket to human triage when$dept_conf < 0.5. The numbers live in the YAML, where you can review and change them.

  4. Route, and degrade on purpose

    Expanso

    A switch output writes each record to its destination. If the call to Jev fails, acatch marks the record jev-unavailable and the same gate still picks a route. Each example page states where that lands, including the ones that fail open as written.

What these examples are

  • Real files. Every page shows the example's own pipeline file, unmodified, as of commit 517c38f of its repository, and serves the same bytes as a download.
  • Validated. All ten pass expanso-edge validate on Expanso Edge v2.1.21, which checks a configuration offline.
  • One live runtime. Log triage ships with a generator, a recurrence counter and a dashboard. The other nine are a pipeline file and sample records.

What they are not

  • Not a Jev account. You supply the Jev endpoint and key. Nothing here provisions one.
  • Not production wiring. Every route writes to a local file. Comments in the YAML mark where a paging, SIEM or work-order webhook goes.
  • Not benchmarks. No accuracy, latency or cost figures are published for these pipelines, so these pages quote none. Two of the files mention a latency in their own comments or description; those are the examples' words, shown because the files are shown whole, and not measurements.

Frequently asked questions.

Expanso is the deterministic part: it receives the record, shapes it, fingerprints and counts it where the example needs history, applies fixed thresholds, and routes it. It applies the same fixed rules every time, with no model involved; that is a claim about what happens to the record, not about timing. Jev is the non-deterministic part: it answers questions that need judgment, such as how severe a log line is or whether a ticket sounds urgent. On a pass where Jev answers, the record crosses to Jev once and comes back with answers the pipeline compares against numbers. In log triage, a record Jev did not answer for is held and sent to Jev again on each retry.

Start with the half you can predict.

Set up Expanso Edge, point a pipeline at your Jev endpoint, and validate it before anything runs.