All guides

Create Your First Guardrail Profile

Protect secrets and personal data in prompts and responses with a guardrail profile, and apply it to every policy as your baseline.

10 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02How guardrails fit around a request
  3. 03Start from a template
  4. 04Pick an action for each side
  5. 05Name it and save
  6. 06Make it your organization baseline
  7. 07Test it with a real request
  8. 08Roll out in steps
  9. 09What is scanned
  10. 10If something goes wrong

01

What you'll set up

In about ten minutes you will have a guardrail profile that detects credentials in prompts and responses, applied to every policy as your organization baseline. You will test it with a real request.

  • A profile created from a template
  • An action for prompts and an action for responses
  • The profile set as your organization baseline
  • A test that shows what the model actually receives

You need an owner or admin role and an AI plan. Nothing is scanned until you create a profile, so you decide what is checked.

02

How guardrails fit around a request

A profile has two sides. The input side checks the prompt before it reaches the model. The output side checks the response before it reaches your user.

Where the checks run
  1. 1Your app sends a prompt

  2. 2Input rules

    Redact, block, or observe

  3. 3The model

  4. 4Output rules

    Redact, block, or observe

  5. 5Your user sees the answer

03

Start from a template

Open AI → Policies and find Guardrail profiles. Choose Start from a template. A template is a starting point: once you create a profile, it is yours to change, and it never follows later template changes.

TemplateWhat it doesStart here if
Monitor onlyRecords credential findings and changes nothingYou want to see what is in your traffic first
Secrets redactionMasks credentials in prompts and responsesYou want credentials gone but work to continue
StrictBlocks any prompt or response containing a credentialCredentials must never move
US personal data redactionAdds editable rules for email, SSN, phone, and card-like numbersYou handle US personal data
European personal data redactionAdds editable rules for email, IBAN, phone, and card-like numbersYou handle European personal data
AI → Policies → Guardrail profiles → Create guardrail profile
Start from
Secrets redaction

Redacts credentials (API keys, tokens, private keys) from prompts before they reach the model and from responses before they reach the user.

Pick the template closest to what you need.

04

Pick an action for each side

Prompts and responses each have an Action on detection. They are set separately, so you can redact credentials in prompts and block them in responses.

ActionWhat happensTypical use
ObserveRecords the finding. Nothing changes.The first week of a rollout
RedactReplaces the match with a marker before the model, or the user, sees itCredentials and personal data
BlockStops the request or response with a clear messageContent that must never leave

Each side also has a Secrets toggle. It switches on the built-in credential detection: API keys and tokens from major vendors, private keys, bearer tokens, and password or secret assignments.

05

Name it and save

Give the profile a clear name, such as Company baseline. Save it. The profile is live as soon as it is saved, and it keeps a version history from that point.

06

Make it your organization baseline

Switch on Org baseline in the profile and the profile applies to every policy. A policy can attach one more profile to add protection for a specific team.

AI → Policies → Guardrail profiles → Create guardrail profile
Org baseline
Applies to every policy, merged with the policy's own profile; the stricter setting wins.On
One baseline, applied to every policy.
Baseline saysTeam profile saysResult
Redact credentialsBlock the codename Project FalconCredentials are redacted everywhere. The codename is blocked for that team.
Redact credentialsObserve credentialsCredentials are still redacted. The stricter action wins.

Profiles are evaluated as written and the strictest outcome wins. A team profile can add protection but never weaken the baseline. To attach a profile to one policy, choose it in the policy form's guardrail profile field.

07

Test it with a real request

Send a prompt that contains a fake credential through your virtual key, and see what happens.

bash
curl https://api.cloptima.ai/v1/ai/chat/completions \
  -H "Authorization: Bearer $CLOPTIMA_VIRTUAL_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "gpt-4o-mini", "messages": [{"role": "user", "content": "Debug this config: api_key = abc123def456ghi789"}]}'
Prompt actionWhat you see
ObserveA normal response. The finding is recorded.
RedactA normal response. The model received [REDACTED_SECRET] instead of the key.
BlockHTTP 403 with the reason gateway_guardrail_blocked
HTTP 403
{
  "error": "Your AI request was blocked because it matched a configured safety rule.",
  "reason": "gateway_guardrail_blocked",
  "violations": ["secret_assignment"]
}

08

Roll out in steps

A guardrail you trust is one you have watched work.

  1. 1

    Week 1: Observe

    Run the baseline in Observe and review findings in the audit log.

  2. 2

    Week 2: Redact credentials

    Switch the credential rules to Redact. Work continues, and secrets stop reaching models.

  3. 3

    Week 3: Add personal-data rules

    Start from a regional template and keep the new rules in Observe while you tune them.

  4. 4

    Week 4: Block what must never leave

    Move the most important rules to Block.

09

What is scanned

Each request is scanned on its new message, not on the earlier conversation, which was scanned when it was new. Responses are scanned on the text the model generates.

If a single new message is extremely long, the gateway scans up to a generous limit. The setting New turn larger than the scan window lets you choose: scan the window and allow the rest, or block the request.

The number of profiles and custom rules you can create depends on your plan.

10

If something goes wrong

Most surprises come from where a profile is attached.

What you seeLikely causeFix
Nothing is detectedNo baseline is set and the policy has no profileSwitch on Org baseline, or attach the profile to the policy
The policy list shows No guardrailsNo baseline exists and the policy has no profileCreate a baseline or attach a profile
Too much is blockedThe action is stricter than you intendedSet the side to Observe or Redact while you tune
A rule seems ignoredThe rule is on the other side (prompts or responses)Check which side the rule is on

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial