Workspace default, instance override
Guardrails use a simple operating model. A workspace default applies to every DPanel instance in the account. Each instance or project can override that default when it needs a stricter or more specific policy.
That gives operators one place to define the baseline without losing per-project control.
Enforced before the model runs
Guardrails are enforced server-side on every model call before the model runs. They are not just UI warnings and they are not left to an AI worker to remember.
The policy can allow, flag, redact, or block a request depending on the category and configured action.
The four guardrail categories
Budget Policies set spend limits and request or token rate caps. Model & Provider Access controls which models and providers an instance may use.
Prompt Injection policies detect jailbreak and instruction-override attempts. Sensitive Info Detection identifies PII, credentials, and personal data so DPanel can flag, redact, or block the request.
Next step
Turn this concept into a visible workflow with teams, approvals, grounding, and handoff.
Compare Pack and BYOK