Runtime Guardrail

Runtime Guardrail An architecture diagram generated by Archify. Policy card · same rule as CI · Layer 01 Govern-as-Code Policy card same rule as CI Request · prompt, context · Architecture component Request prompt, context Input guardrail · allow / block · Layer 04 Runtime Controls & Observability Input guardrail allow / block Model or agent · acts on the call · Layer 04 Runtime Controls & Observability Model or agent acts on the call Output guardrail · allow / block / redact · Layer 04 Runtime Controls & Observability Output guardrail allow / block / redact Response · or tool call · Architecture component Response or tool call Assurance store · decision events · Layer 05 Assurance & Continuous Compliance Assurance store decision events Circuit breaker · on a defined breach · Layer 04 Runtime Controls & Observability Circuit breaker on a defined breach allow allow enforce enforce event event breach Layer 01 Govern-as-Code Layer 04 Runtime Controls & Observability Layer 05 Assurance & Continuous Compliance Legend Backend Database Security External

Enforce at the point of action

  • • The input guardrail screens prompts and retrieved context before the model sees them
  • • The output guardrail screens generations and tool calls before they take effect
  • • A guardrail that only logs is observability mistaken for control

One rule, many events

  • • Both sides enforce the Policy Card that CI evaluated
  • • Every call emits agent, direction, rule, decision and time to the assurance store
  • • A defined breach signals the breaker, which withdraws the agent's autonomy wholesale

First step

  • • Put one guardrail on each side of one agent
  • • Make it emit before you make it clever