Skip to main content

Policies

A policy is an ordered or parallel bundle of guardrail steps. Create one with New policy in the Guardrails page header, then edit the flow in the builder at /guardrails/policies/[id].

Create a policy​

New policy opens Create policy:

  • Name and an optional Description
  • Start from a template or Blank policy. Templates add their Garden guardrails as steps and create any that aren't configured yet:
    • Data protection: Detect PII, Secrets present
    • Prompt attack defense: Detect jailbreak, Data exfiltration, Malicious code fences
    • Safe customer chat: Toxic language (rules), Insults & personal attacks, Harmful violence, Harmful self-harm
  • How steps run: Run in order (recommended) or Run all at once

Create and open builder creates the policy and opens the builder. A new policy is not enforced until you attach it.

Execution​

ModeUI labelBehavior
PARALLELRun all at onceEvery step runs; any failing step blocks the request
FLOWRun in orderSteps run in order, and each step decides what happens next (see Steps)

Switch modes in the builder's Pipeline panel.

Steps​

Each step references a configured guardrail (Garden, custom or vendor). Use Add a step to add one. Select a step to Change its guardrail, move it up or down, or remove it.

In Run in order, each step has three outcomes:

OutcomeChoices (default first)
When it passesRun next step, Allow request, Block request
When it failsBlock request, Run next step, Allow request
If it can't runSame as when it fails, Block request, Run next step, Allow request

Allow request stops and lets the request through, skipping later steps. After the last step the request is allowed. A guardrail that redacts on a match passes the redacted text on; other guardrails fail the check.

In Run all at once there are no per-step choices: every step runs and any failure blocks.

Builder​

  • The header shows the policy's state (On / Off), step count, mode and how many places it applies.
  • Try it runs a sample Prompt or Response through the pipeline on screen, including unsaved changes, without calling the gateway. Each step shows its result.
  • Where it applies lists attachments and adds new ones (Attachments). It uses the last saved pipeline.
  • Changes show an Unsaved changes bar; Save or Save policy stores them. Policy actions → Delete policy removes the policy, which stops applying everywhere it was attached.

Only writable platform admins can change a policy in the builder. Everyone else can view and test it.

Enable / disable​

The Policy on switch in the builder header turns a policy on or off. A disabled policy is not evaluated, even if it still has attachments. Use this as a kill switch without deleting attachments.

Policy directory​

The Policies tab lists each policy with On / Off, description, mode, numbered steps and Applies to (its attachments). Not applied anywhere · not enforced flags policies without attachments. Search by name. Open builder (or View for non-admins) opens the builder; admins can also delete from here. An empty directory offers Create a policy.

Who can write​

Creating, editing and deleting policies is a platform-admin write. Everyone can browse the directory.

Next: attach the policy.