Custom and vendor guardrails
Besides Garden cards (BUILTIN), the Guardrails tab can create two other kinds.
Custom
A sandboxed script that can allow, block or modify the prompt or completion. Set mode to PRE, POST or BOTH.
Use custom scripts for org-specific patterns, allowlists, or transformations that are not in the Garden.
Vendor
External scanners. Fail-open is optional (if the vendor is down, the step passes).
| Type | What it calls |
|---|---|
OPENAI_MODERATION | OpenAI Moderation API, using a stored provider credential |
AZURE_CONTENT_SAFETY | Azure AI Content Safety |
WEBHOOK | Your HTTPS endpoint |
Vendor steps also appear as Garden cards (toxic language, NSFW, Llama Guard / Shield Gemma stand-ins). Playground dry-runs vendor and LLM critic calls when a credential is configured. Custom Starlark is still gateway-only.
Directory
The Guardrails tab lists every instance: name, kind, mode, enabled, and how many policy steps use it. Disable an instance to stop it everywhere it is referenced without deleting the policy.