Step 1 — Provider
Pick one card, then Continue:Step 2 — Configure (all providers)
- Enter Profile name (placeholder
e.g. Production guards). - Follow the provider-specific path below.
- Click Save profile (optional Test connection for non-Phinite when supported).
on_violation defaults to block_turn.
Path — Phinite
See the full Control library walkthrough: Phinite Guardrails. Summary: open Control library → filter by Compliance framework → enable controls under Before the model / After the model / Session data → set Block / Log only / Redact per control → Save profile.Path — AWS Bedrock / Azure / GCP
Credentials
- Section Credentials.
- How do you want to provide secrets?
- Enter credentials — fill fields inline
- Use Environment secret — pick a workspace env secret (
envencryptid)
- Fill required fields:
AWS Bedrock
Resource
Needs IAM permission
bedrock:ApplyGuardrail. Topic/PII filters stay in the AWS console.
Azure Content Safety
From Azure Portal → Content Safety (or Cognitive Services) → Keys and Endpoint.
GCP Model Armor
Resource: Template / policy ID.
Test and docs
- Test connection when the provider supports it and credentials are ready.
- Documentation / setup guide opens the in-product credentials guide.
Save
Save profile → profile appears in Library with the provider badge.After create
- Attach to the flow or an agent.
- Confirm In Use on LLM Governance.
- Save + Build the Agent Graph.

