Set security rules for AI agents.
Built into Connic.
Untrusted input is evaluated before execution and the final answer before release. Built-in or custom Python policies can block, warn, or redact, with every decision attached to the trace.
Read the guardrails docs- passed
prompt_injectionInput - redacted
piiInput - completed
agent executionRuntime - passed
moderationOutput - passed
system_prompt_leakageOutput
Check inputs and responses for security risks
Use guardrails to check incoming content before the agent processes it and responses before they are released. Every decision is logged, including when processing continues.
run_after_on_block: false is set.Detect risks with rules and AI
Combine fast standard checks, context-aware AI checks, and custom Python rules to suit your application.
| Rule | Direction | Modes | Purpose |
|---|---|---|---|
prompt_injection | Input | block · warn | Detect instruction-hijacking patterns |
pii | Input | block · warn · redact | Detect or replace configured PII entities |
moderation | Both | block · warn | Check configured safety categories |
topic_restriction | Input | block · warn | Classify requests against allowed or blocked topics |
regex | Both | block · warn | Apply application-specific text patterns |
pii_leakage | Output | block · warn · redact | Keep configured PII out of responses |
system_prompt_leakage | Output | block · warn | Compare output with the actual system prompt |
relevance | Output | block · warn | Classify whether the answer stayed relevant |
data_exfiltration | Output | block · warn | Flag suspicious external URLs and encoded payloads |
External provider options are available for prompt injection and moderation checks. Review every built-in guardrail and provider.
Start with four security checks for AI agents
Check for prompt injection, personal data, harmful responses, and system prompt disclosure. Use execution traces to adapt the configuration to your application.
guardrails:
input:
- type: prompt_injection
mode: block
- type: pii
mode: redact
output:
- type: moderation
mode: block
- type: system_prompt_leakage
mode: block| Span | Status |
|---|---|
guardrail:prompt_injection | passed |
guardrail:pii | redacted |
guardrail:moderation | passed |
guardrail:system_prompt_leakage | passed |
blockReplace the unsafe response or skip agent execution for an input violation.
warnRecord the violation as a trace span and let processing continue.
redactReplace detected PII with typed placeholders on supported PII checks.
Application-specific guardrails in Python
Custom checks cover tenant authorization, record shape, internal policy, and other application-owned validation.
from connic import GuardrailResult
import re
def check(content: str, context: dict) -> GuardrailResult:
"""Require a ticket ID before this agent runs."""
if not re.search(r"TICKET-\d{4,8}", content):
return GuardrailResult(
passed=False,
message="Include a valid ticket ID."
)
return GuardrailResult(passed=True)Required export
A matching file under guardrails/ exports check(content, context).
Sync or async
A policy or authorization service can handle cases where a local rule is not enough.
Fail through the configured mode
An exception is logged and handled as a violation: warn continues; block stops processing.
Logs stay attached
Print, stderr, and standard logging appear under guardrail.<name> on the same run.
An input guardrail cannot depend on context values that before middleware has not created yet. The request is available from content; authorization checks that require middleware-enriched context belong in middleware or an output guardrail.
Keep exploring
Approvals
Put a human before sensitive tool calls.
Observability
Inspect every evaluation in its run trace.
AI Governance
Turn runtime evidence into a governed record.
Testing
Exercise safety behavior before release.
Tools
Keep business actions narrow and explicit.
Managed Runtime
Enforce runtime limits around every run.