What to detect
Credential patterns, personal information and enterprise-defined fields, according to supported rules and versions.
Place sensitive-data checks, model access controls and tool authorization in the actual execution path to enforce enterprise rules.
Check documents and context before they are sent.
Check tool actions, target resources and permissions.
Record policy decisions, approvals and event outcomes.

Identify enterprise-defined sensitive fields, then decide handling based on the destination model and task scope.
Credential patterns, personal information and enterprise-defined fields, according to supported rules and versions.
Block, redact or allow; exceptions follow an explicit authorization process.
Check allowed models, addresses and resource scopes instead of sending to arbitrary endpoints by default.
Redaction may affect quality. Validate false positives, missed detections and usability.
Check identity, parameters and target systems before execution, with human approval for high-risk actions.
Tool allowlists, target domains, commands and parameter constraints.
Provide only the permissions needed for the current task.
Provide credentials through controlled mechanisms; short-lived or task-bound support depends on the version.
Send sensitive configuration changes and high-risk actions to the responsible owner.
Configure gateways, credentials and logs to enterprise needs, with clear connections to management services and external models.
Plan controlled request processing in an enterprise intranet or VPC.
Define policy distribution, metadata reporting and operational access.
Use enterprise-authorized model keys, with explicit access and storage arrangements.
Retain metadata and policy outcomes as needed; full-content logging is configured separately.
Link requests, tool actions and approvals to investigate issues and refine rules.
Time, user or application, agent, model, tool, policy outcome and correlation ID.
Detect → block or request review → alert → trace → review rules.
Control log access through permissions and mask sensitive content where needed.
Audit supports investigation; it neither replaces all real-time blocking nor proves a path is entirely tamper-free.
Map model entry points, agents and business tools, then locate policy enforcement for each call type.
Model calls through the enterprise gateway can be checked according to configuration.
Tool actions integrated at the execution endpoint can enforce parameters and permissions.
Direct model calls and unintegrated tools need separate inclusion; they are not covered by default.