Custom AI applications can process prompts that contain sensitive data, unsafe content, attack attempts, or requests that violate your organization's AI usage policies. Blocking access to these applications can reduce risk, but it can also limit the value of approved AI workflows.
The Guards Interaction Policy lets you control how specific guards handle AI interactions by inspecting content in real time and applying actions when risky or non-compliant content is detected. Instead of applying the same protection to every guarded workflow, you can create granular rules for selected guards and assign the engine profiles and actions that match the security requirements of each application.
Using Guards Interaction Policy rules, you can detect, block, anonymize, or monitor AI interactions based on your organization's security and governance requirements. This helps you protect sensitive information and enforce AI usage policies for AI applications you build without disrupting legitimate business use.
Before you create rules, enable the Guards Interaction Policy for end users in the Cato Management Application.
To enable the policy:
- From the navigation menu, select AI Security.
- Under AI App Security, select Guards Interaction Policy
- Enable the AI Apps Policy toggle.
Rules in the Guards Interaction policy are evaluated regardless of their position in the rule base. If more than one rule is triggered, the stricter action is applied. For example, if there is a rule with a Monitor action, and another rule with a Block action, the Block action will be applied.
Configure a Guards Interaction Policy rule to enforce AI Security controls on matching traffic.
Before you create a rule, understand how scope affects enforcement:
Scope |
Enforcement behavior |
|---|---|
Guard only |
Applies to all traffic through the selected AI Gateway Guard |
Specific Homegrown Agents |
Applies only to traffic from the selected homegrown agents |
If you are not using an AI Gateway, the scope is the same for Guard or Homegrown Agent.
To create a rule:
- From the AI Interaction Policy page, click New.
- In the General section, configure the fields, for example Name and Description, as well as the position of the rule.
- In the Guards section, select the specific guards that the rule applies to, or click Select All to apply the rule to all guards.
-
In the Engine Profile section, select the profile used to evaluate AI prompts.
Engine profiles are the data type against which the content is checked. For example, PII to see if there are Social Security numbers included in the prompt.
- In the Action section, select the action to apply when a prompt matches the content profile, such as Block.
- To determine the scope of the rule, select at least one Direction on which to apply the rule.
- Click Save.
Verify Policy Enforcement
Verify policy enforcement by sending test traffic that matches the rule scope and engine profile.
To verify policy enforcement:
Send a test request from your homegrown agent.
Include content that matches the selected Engine Profile
From the navigation menu, select AI Security > Session Explorer
Filter by your Guard or Agent
Confirm that Violated Rules shows the policy rule
Traffic that does not match the selected Engine Profile shows no violated rules and passes through normally.
0 comments
Please sign in to leave a comment.