Garden catalog
The Garden tab is a Hub-style catalog of first-party validators: search, quick and facet filters, tagged cards, multi-select, and a config drawer.
A card does nothing until it is added, placed on a policy, and that policy is attached.
Engines
| Engine | Latency | How it runs |
|---|---|---|
| Rule | Zero extra model latency | In-process regex, phrases, JSON Schema, SQL/HTML checks |
| LLM | Extra critic call | OpenAI-compatible chat completion using a stored credential |
| Vendor | Extra vendor call | OpenAI Moderation or Azure Content Safety (Hub ML cards map here) |
Coming-soon cards (Valid address, Wiki provenance, embeddings/NLI, Presidio, endpoint probe) are listed but cannot be added.
Search and filters
Search validators by name, description or tag. Sort by Popularity, Name or Engine.
Quick filters: LLM, Security, Data, Brand, Safety.
Filters combine with AND across groups and OR within a group. Each option shows how many cards match:
- Use case — Chatbots, Customer Support, Structured data, RAG, CodeGen, Summarization, Text2SQL
- Risk category — Brand risk, Formatting, Etiquette, Jailbreaking, Data Leakage, Code Exploits, Invalid Code, Factuality
- Infrastructure — Rule, LLM, Vendor
- Content type — string, list, sql, code, integer, object, float
Clear resets the filters. Save filter view stores the search, filters and sort in this browser and restores them next time.
While Detect jailbreak isn't configured, or neither Data exfiltration nor Detect PII is, a banner recommends jailbreak and data-leakage validators. View recommendations filters to the Jailbreaking and Data Leakage risks; dismissing the banner hides it in this browser.
Adding cards
Platform admins can add cards:
- Open a card for type-specific config (regex, keywords, schema, critic model, credential), then Add guardrail (or Save settings if it's already configured).
- Select + Add selected creates instances with defaults. Cards that require config open the drawer.
- Add to policy opens Add selection to a policy. Pick a Policy, or keep Create a new policy and give a New policy name. Missing instances are created and appended as steps. New policies created this way Run all at once; change that in the builder.
Rule cards
Includes the original Garden (PII, secrets, jailbreak, SQL predicates, toxicity keywords, advice packs, word count, URL filter) plus Hub-parity formatters: contains/ends-with, regex, cucumber expressions, valid JSON/schema/length/range/choices/URL/HTML/OpenAPI/SQL, reading level/time, prompt-leak fuzzy match, web sanitization, price quotes, drug names, and redundant sentences.
JSON schema now validates against config.schema, not merely “is this JSON?”. Use Valid JSON for parse-only.
LLM and vendor cards
LLM cards store { credentialId, model, criteria, failOpen } and skip nested guardrails on the critic call (X-Zea-Internal: guardrail-critic).
Vendor Garden cards create VENDOR instances (OPENAI_MODERATION or AZURE_CONTENT_SAFETY). They stand in for Hub ML validators (BERT toxic, Llama Guard, Shield Gemma, NSFW) without shipping those weights.
Playground
Rule, LLM, and vendor steps dry-run in the Playground. Custom Starlark still runs only on the gateway.