Skip to main content
Create profiles from Studio Governance → LLM Governance → New profile. Wizard steps: ProviderConfigure.

Step 1 — Provider

Pick one card, then Continue:

Step 2 — Configure (all providers)

  1. Enter Profile name (placeholder e.g. Production guards).
  2. Follow the provider-specific path below.
  3. Click Save profile (optional Test connection for non-Phinite when supported).
Profile field on_violation defaults to block_turn.

Path — Phinite

See the full Control library walkthrough: Phinite Guardrails. Summary: open Control library → filter by Compliance framework → enable controls under Before the model / After the model / Session data → set Block / Log only / Redact per control → Save profile.

Path — AWS Bedrock / Azure / GCP

Credentials

  1. Section Credentials.
  2. How do you want to provide secrets?
    • Enter credentials — fill fields inline
    • Use Environment secret — pick a workspace env secret (envencryptid)
  3. Fill required fields:

AWS Bedrock

Resource Needs IAM permission bedrock:ApplyGuardrail. Topic/PII filters stay in the AWS console.

Azure Content Safety

From Azure Portal → Content Safety (or Cognitive Services) → Keys and Endpoint.

GCP Model Armor

Resource: Template / policy ID.

Test and docs

  • Test connection when the provider supports it and credentials are ready.
  • Documentation / setup guide opens the in-product credentials guide.

Save

Save profile → profile appears in Library with the provider badge.

After create

  1. Attach to the flow or an agent.
  2. Confirm In Use on LLM Governance.
  3. Save + Build the Agent Graph.