Deterministic pipelines. Judgment where it counts.
Expanso does the part of a pipeline that must come out the same every time: shape, fingerprint, count, route. Jev does the part no rule can write: is this actionable, how severe, whose problem. Ten real pipelines show exactly where one hands off to the other.
POST /logs- Receive
- Wait
- Fingerprint
- Count
- Bypass
- Ask Jev
- Gate
- Log
- Record
- Route
actionableseverityteamrecurrence_concern
pagenotifyreviewarchive
Two halves of one pipeline
Most of a pipeline should never surprise you. One step in it needs judgment. Putting both in the same tool makes the predictable part unpredictable. These examples keep them apart, and the seam between them is a single HTTP call you can read.
The substrate
Expanso, deterministicReceives the record, normalizes it, fingerprints it, counts how often it has been seen, applies fixed thresholds, and writes it to the right place. The same fixed rules every time, with no model involved. It runs on nodes you control, next to where the data is created.
- shape
- fingerprint
- count
- gate
- route
The judgment layer
Jev, judgmentAnswers typed questions about one record at a time. It returns values a pipeline can compare against a number, so its judgment arrives in a form the deterministic half can act on.
- actionable
- severity
- team
- recurrence concern
How the handoff works
The same four moves appear in all ten pipelines.
Shape the record
ExpansoParse it, stamp it, and add the context a judgment needs. Log triage adds a fingerprint and an occurrence count, then archives known-routine lines itself so they never reach the model. Sensor triage attaches the asset's baseline. None of this involves a model.
Ask typed questions
JevThe pipeline posts the record with a set of questions. Each has a type that fixes the form of the answer:
noulA yes-or-no question answered as a number from 0 to 1.choiceOne of the named options, with a confidence.scoreA position on a five-step scale, 0 to 4, each step described in the request.
Gate on the answers
ExpansoFixed thresholds, checked in order, turn Jev's answers into one route. The ticket router pages on-call when
$urgent >= 0.9and sends a ticket to human triage when$dept_conf < 0.5. The numbers live in the YAML, where you can review and change them.Route, and degrade on purpose
ExpansoA
switchoutput writes each record to its destination. If the call to Jev fails, acatchmarks the recordjev-unavailableand the same gate still picks a route. Each example page states where that lands, including the ones that fail open as written.
Ten examples, ten handoffs
Each page shows the stages in two lanes, the questions Jev is asked, the exact thresholds Expanso applies, and the full pipeline file with every line marked by who runs it.
- Log triageExpanso runsreceive · wait · fingerprint · count · bypass · gate · log · record · routeJev is askedactionable · severity · team · recurrence_concern
- Support ticket routerExpanso runsreceive · shape · gate · routeJev is askeddepartment · intent · frustration · urgent
- Sensitivity maskingExpanso runsreceive · shape · gate · mask · routeJev is askedsensitivity · contains_pii · contains_credentials
- Sensor anomaly triageExpanso runsreceive · shape · gate · routeJev is askedanomaly · dispatch
- Agent guardrailExpanso runsreceive · shape · gate · routeJev is askedintent_match · risk
- Smart samplingExpanso runsreceive · shape · gate · sample · routeJev is askedinteresting
- SOC pre-filterExpanso runsreceive · shape · gate · routeJev is askedthreat · escalate
- Data quality firewallExpanso runsreceive · shape · gate · routeJev is askedquality · conformant
- Moderation pre-filterExpanso runsreceive · shape · gate · routeJev is askedcategory · needs_human
- Feedback minerExpanso runsreceive · shape · gate · routeJev is askedtopic · sentiment · churn_risk
What these examples are
- Real files. Every page shows the example's own pipeline file, unmodified, as of commit
517c38fof its repository, and serves the same bytes as a download. - Validated. All ten pass
expanso-edge validateon Expanso Edge v2.1.21, which checks a configuration offline. - One live runtime. Log triage ships with a generator, a recurrence counter and a dashboard. The other nine are a pipeline file and sample records.
What they are not
- Not a Jev account. You supply the Jev endpoint and key. Nothing here provisions one.
- Not production wiring. Every route writes to a local file. Comments in the YAML mark where a paging, SIEM or work-order webhook goes.
- Not benchmarks. No accuracy, latency or cost figures are published for these pipelines, so these pages quote none. Two of the files mention a latency in their own comments or description; those are the examples' words, shown because the files are shown whole, and not measurements.
Frequently asked questions.
Expanso is the deterministic part: it receives the record, shapes it, fingerprints and counts it where the example needs history, applies fixed thresholds, and routes it. It applies the same fixed rules every time, with no model involved; that is a claim about what happens to the record, not about timing. Jev is the non-deterministic part: it answers questions that need judgment, such as how severe a log line is or whether a ticket sounds urgent. On a pass where Jev answers, the record crosses to Jev once and comes back with answers the pipeline compares against numbers. In log triage, a record Jev did not answer for is held and sent to Jev again on each retry.
No. Jev answers typed questions and returns a value and, for choices, a confidence. The route is chosen by a gate in the Expanso pipeline: fixed thresholds checked in order. That keeps the routing rules in a YAML file you can read, review and change.
Each pipeline catches the failed call, marks the record jev-unavailable and continues, so no record is dropped by the failure itself. Where it lands depends on that example’s defaults. Log triage holds the record and asks again, up to 15 attempts, before sending it to review. The agent guardrail, the data quality firewall and moderation fail closed, to block, quarantine or review. Others, such as sensitivity masking, resolve to their permissive route as written. Each example page states its own outcome.
No. The examples call Jev with the general http processor inside a branch, so the request and the response mapping are visible in the YAML. Nine of the ten send a bearer token from TYPESAFE_API_KEY. You supply the endpoint and the key.
All ten files pass expanso-edge validate on Expanso Edge v2.1.21, which checks the configuration offline. Log triage is the example with a full live runtime in its package. The other nine ship as a pipeline file and sample records, and their READMEs mark the live runtime as coming next. Expanso has not published measured results for any of them, so these pages quote none. Two of the files mention a latency in their own text; those are the examples’ words, not measurements.
Start with the half you can predict.
Set up Expanso Edge, point a pipeline at your Jev endpoint, and validate it before anything runs.