PARTNER ADMIN GUIDE
Configure tenant guardrails
Apply governance controls to tenant interactions, restrict unsafe or off-topic content and review which policies are available, active and enforcing.
Scope: individual tenant
How guardrails work
A guardrail capability is the underlying control. A guardrail policy is how that control is configured for one tenant.
- Guardrail capability
- The underlying control, such as prompt-injection protection, PII masking or topic restriction.
- Guardrail policy
- The tenant-specific configuration that selects a capability, optionally limits it to an environment and supplies any capability-specific settings.
Tenant interaction
↓
Matching environment policy
↓
Guardrail capability
↓
Monitor or enforce
↓
Status and violation indicatorsStatus definitions
- Active guardrails
- Policies currently active for the tenant.
- Enforcing
- Policies operating in enforcement mode rather than monitoring-only mode.
- Violations (7d)
- The number of recorded policy violations during the previous seven days, when violation data is available.
- Availability
- The platform-reported availability status for the selected guardrail capability.
- Monitor
- Observes or records matching activity without applying the full enforcement behaviour, where supported.
- Enforce
- Actively applies the configured policy behaviour.
- Enabled
- Controls whether the individual policy is switched on.
Guides in this section
Understand guardrail status
Read the active, enforcing, availability and violation indicators.
Add a built-in guardrail
Select a capability, target an environment and configure its rules.
Configure guardrail capabilities
Understand the settings used by PII, prompt-injection, profanity and topic controls.
Add a custom guardrail
Register an approved capability ID with raw JSON configuration.
Review and export policies
Search, filter and export the tenant's policy configuration.
Troubleshoot guardrails
Resolve unavailable capabilities, permission errors and policies that do not apply as expected.
Before you begin
- Open the correct customer tenant.
- Decide whether the policy applies to every environment or one named environment.
- Identify the guardrail capability required by the customer use case.
- Prepare any blocked words, additional masked words or allowed topics.
- For a custom guardrail, obtain the exact approved capability ID and configuration schema.
- Decide whether the policy should initially monitor or enforce.
- Prepare representative test inputs, including acceptable content and content that should be flagged.
Review the Guardrails page
The Guardrails page is the single view of policy status, filters and policy actions for the tenant.
- Active guardrails
- Shows the number of active policies for the tenant.
- Enforcing
- Shows how many policies are operating in enforcement mode.
- Violations (7d)
- Shows the recent violation count when data is available.
- Status label
- The label beside the page title summarises whether the tenant currently has active guardrails.
Filters
- Search for a guardrail by name or capability.
- Filter by environment.
- Filter by All, Enforce or Monitor.
- Clear filters when an expected policy is missing from the table.
| Column | Shows |
|---|---|
| Guardrail | The policy and the capability it uses |
| Environment | The environment the policy is limited to, when one is set |
| Availability | The platform-reported availability of the capability |
| Config | The configuration supplied for the policy |
| Mode | Whether the policy monitors or enforces |
| Updated | When the policy was last changed |
| Enabled | Whether the individual policy is switched on |
| Actions | The row actions available in the current deployment |
The overview screenshot above represents a tenant with no configured guardrails. It is an example of the interface, not an example of a configured policy set.
Add a built-in guardrail
The Add guardrail form changes according to the selected capability, so complete only the fields it shows.
- 1Open the customer tenant.
- 2Select Guardrails.
- 3Select Add guardrail.
- 4Choose the required capability.
- 5Enter an environment when the policy should apply only to that environment.
- 6Leave Environment blank when the policy should apply to all environments.
- 7Complete the capability-specific settings.
- 8Select Save.
- 9Find the saved policy in the table.
- 10Review its Availability, Mode and Enabled columns.
- 11Test the policy with representative inputs.
- 12Move to enforcement only after confirming that expected interactions continue to work.
Configure built-in capabilities
Different guardrail capabilities expose different configuration fields. Configure only the settings shown for the selected capability.
PII masking
- Select PII masking as the capability.
- Optionally target one environment.
- Enter one blocked word or phrase per line.
- Leave the blocklist empty when no additional terms are required.
- Test the policy using fictional data rather than real personal information.
Prompt-injection guard
- Select Prompt-injection guard.
- Enter an environment only when the control should be environment-specific.
- Save the policy.
- Confirm availability before enabling enforcement.
- Test with normal user requests as well as representative attempts to override instructions or expose restricted behaviour.
Profanity filter
- The capability includes a built-in list.
- Use Extra words to add tenant-specific terms.
- Enter one word per line.
- Added terms are masked in addition to the built-in list.
- Consider language, regional usage and legitimate business terminology before adding a term.
Topic and scope guard
- Enter one allowed keyword or topic per line.
- The assistant may discuss content matching the configured topics.
- A longer message matching none of the configured terms may be denied as off-topic.
- Include important synonyms, abbreviations, product names and common customer wording.
- Test both legitimate edge cases and clearly unrelated questions.
| Capability | Administrator configures | Typical purpose |
|---|---|---|
| PII masking | Optional environment and blocklist | Protect sensitive information and block specified terms |
| Prompt-injection guard | Optional environment | Guard against attempts to manipulate assistant instructions |
| Profanity filter | Optional environment and extra words | Mask built-in and tenant-specific inappropriate terms |
| Topic/scope guard | Optional environment and allowed keywords | Keep interactions within approved subjects |
| Custom | Capability ID, optional environment and raw JSON | Configure an approved capability not represented by a built-in form |
Capability names and available fields may evolve. Treat the screenshots as examples of the current interface rather than a permanent inventory.
Add a custom guardrail
Custom guardrails require an approved capability ID and valid raw JSON configuration.
- Capability ID
- The exact identifier of the approved guardrail capability, for example one supplied by the platform administrator or capability owner.
- Environment
- Optional environment restriction. Leave blank to apply the policy across environments.
- Config (raw JSON)
- The capability-specific configuration object. It must be valid JSON and conform to the schema expected by the capability.
- 1Confirm that the capability is approved and available on the deployment.
- 2Obtain the exact Capability ID.
- 3Obtain the supported configuration schema and a safe example.
- 4Select Custom from the Capability list.
- 5Enter the Capability ID exactly.
- 6Add an environment only when required.
- 7Enter valid JSON in Config.
- 8Review the JSON for syntax errors.
- 9Select Save.
- 10Confirm the saved policy's Availability status.
- 11Test it in a controlled environment before enforcement.
Review active and enforcing policies
Use the table and filters to confirm what is actually applied to the tenant.
- 1Open Guardrails for the tenant.
- 2Clear the search field.
- 3Select the required environment or All environments.
- 4Select All, Enforce or Monitor.
- 5Review the Availability status.
- 6Confirm the expected Mode.
- 7Confirm that Enabled has the intended value.
- 8Review the Updated date after making a change.
- 9Use the row actions available in the current deployment to inspect or change the policy.
- 10Test the affected tenant interaction after changing enforcement.
Understand the violations indicator
- The summary card reports violations during the previous seven days when data is available.
- Use the indicator to identify whether a policy may need further review.
- A sudden increase may indicate a real threat, an overly broad configuration or a change in user behaviour.
- Compare violation patterns with recent policy or environment changes.
Export policies
Exports support governance review, audit handover and comparison of the tenant's policy configuration.
- 1Open the correct tenant.
- 2Select Guardrails.
- 3Review the policies and environment filters.
- 4Select Export policies.
- 5Save the downloaded export in an approved customer or partner location.
- 6Record the tenant and export date when the file will be used for governance review.
Recommended guardrail rollout
A cautious sequence that reduces false positives and gives the customer confidence in the result.
- 1Agree the customer's governance objective.
- 2Select the smallest relevant capability.
- 3Target a non-production environment first where one is available.
- 4Configure only the required words, phrases or topics.
- 5Save the policy.
- 6Confirm capability availability.
- 7Enable Monitor mode where supported.
- 8Test acceptable, borderline and unacceptable inputs.
- 9Refine the configuration to reduce false positives.
- 10Enable enforcement when the customer approves the behaviour.
- 11Review the seven-day violation indicator.
- 12Export the policy configuration for governance records.
Troubleshoot unavailable guardrails
A forbidden or unavailable state means the policy data could not be retrieved, not that the tenant has no guardrails.
- 1Confirm that the administrator opened the intended tenant.
- 2Confirm that the account has partnership administrator access.
- 3Refresh the Guardrails page.
- 4Return to the tenant overview and reopen Guardrails.
- 5Check whether other tenant administration pages load normally.
- 6Do not add or change policies while the current policy state cannot be retrieved.
- 7Contact the Greentic platform administrator when the forbidden or unavailable state persists, including the tenant identifier, time of the error and a screenshot without sensitive data.
Troubleshooting at a glance
| Problem | Likely cause | Action |
|---|---|---|
| The page shows Forbidden or Status unavailable | The administrator lacks access, the service is unavailable or the tenant data could not be loaded | Confirm tenant permissions, refresh and contact the platform administrator if it persists |
| The form says availability not checked | The selected capability has not yet had its availability confirmed | Save only when appropriate, then review the Availability column |
| A saved policy is not enforcing | It is disabled, unavailable, in Monitor mode or does not match the current environment | Review Availability, Mode, Enabled and Environment |
| No policies appear in the table | Search, environment or mode filters exclude them | Clear the search field and reset all filters |
| A legitimate request is blocked as off-topic | The allowed-keyword list is too narrow | Add relevant synonyms, abbreviations and common customer phrasing |
| A prohibited term is not detected | The term is absent, entered differently or the policy is not applied to the environment | Review the configuration and test the exact target environment |
| A custom policy cannot be saved | The JSON is invalid or the capability ID or schema is unsupported | Validate the JSON and confirm the capability documentation |
| The violation card shows a dash | Violation data or guardrail status is not available in the displayed state | Confirm policy availability and page status before interpreting the result |
| A policy creates too many violations | The rules are too broad or the policy was enforced without sufficient testing | Return to Monitor where supported, refine the configuration and retest |
