Skip to main content

Manage guardrails

Add guardrails at the organization level, choose what to log or block, then require them across all workspaces or enable them only for selected workspaces.

For supported guardrails and provider-specific settings, see the

Add a guardrail

Only organization owners and admins can add, edit, or delete guardrails.

  1. Open Organization → Guardrails.

  2. Click Add guardrail.

  3. Under Pick a guardrail, select the guardrail that matches the risk you want to detect. You can search by name, and guardrails are grouped by category.

  4. Choose how to supply credentials:

    • Managed by Otari: Otari supplies the credential and connection settings. This option appears only when a managed credential is available for the selected guardrail.

    • Bring your own key: Paste the guardrail provider's API key and complete any connection settings shown, such as an endpoint, region, or project ID.

  5. Under Decide what to block, choose where blocking applies:

    • Apply on Input: Stop unsafe prompts before they reach the model provider. This option is selected by default.

    • Apply on Output: Stop unsafe model responses before they reach your users.

  6. Review Enable logging. Otari logs prompt and response detections by default. Click Customize Logging if you want to change either direction.

  7. Choose whether to enable Make organization default.

  8. Complete any required guardrail parameters. Optional behavior settings and raw JSON fields are available under Advanced configuration.

  9. Click Add guardrail.

An input blocked by a guardrail never reaches the model provider. An output guardrail runs after the provider has generated a response, so provider usage and cost may still apply even when Otari blocks that response.

Configure guardrail behavior

  • Logging records detections.

  • Input blocking stops a flagged prompt or response.

  • Output blocking stops flagged prompts.

Guardrails block at least one direction and can additionally log detections.

Set the organization default

Turn on Make organization default to require the guardrail in every workspace. Individual workspaces cannot turn off an organization default.

If you leave this setting off, the guardrail is available to every workspace but inactive by default.

Each workspace can choose to turn it on from its **Guardrails** page.

Control workspace access

Once a guardrail exists at the organization level:

  1. Open the workspace you want to manage.

  2. Open Guardrails in the workspace navigation.

  3. Find the guardrail under Managed guardrails or BYOK guardrails.

  4. For an optional guardrail, turn the workspace switch on or off.

Organization defaults show Required by the organization instead of a switch. To make one optional, edit it in Organization Settings → Guardrails and turn off Make organization default.

Workspace settings change only whether the guardrail is enabled. Its input mode,

output mode, logging, credentials, and parameters continue to come from the

organization configuration.

If a guardrail shows Degraded, Misconfigured, or Unavailable, follow the recovery message displayed beside the status before relying on it.

Edit or delete a guardrail

From Organization Settings → Guardrails:

  • Click the edit icon to change credentials, blocking, logging, the organization default, or guardrail parameters. The guardrail cannot be changed after creation.

  • Click the delete icon to remove the guardrail and its workspace settings.

Deleting a guardrail cannot be undone.

Did this answer your question?