Before you start
- You need workspace admin permission to edit Guardrails for a workspace.
- Organization Owners and Admins can also edit the organization baseline, which applies across its workspaces.
- Open Admin Settings → Guardrails.
Choose where a protection applies
Built-in identifiers and custom patterns appear in the same table. Search for an identifier, or filter the table by scope or type.
An organization admin can lock a built-in rule at the organization scope. A locked rule stays on for every workspace until an organization admin unlocks it. A custom pattern cannot be locked. If an organization rule is on but unlocked, a workspace admin can turn it off for their workspace.
Only an enabled rule or pattern produces a placeholder when it matches.
Add a custom pattern
Use a custom pattern when your team has a structured identifier format that the built-in protections do not cover. The pattern is a regular expression that describes the format; do not enter real identifier values. Make the pattern specific to your identifier. Avoid broad checks such as a generic UUID pattern, which could mask unrelated values the agent needs to see.1
Start a pattern
In Admin Settings → Guardrails, click Add pattern. The new pattern starts at the Workspace scope.
2
Name and categorize it
Enter a Name and choose a suggested Category or type one. The category describes the kind of value an agent should see in its place. Categories used by built-in protections are reserved.A matched value is replaced with a placeholder such as
ct:pii:v3:<category>:<hash>.3
Describe the format and save
Enter the regular expression in Pattern, then click Save. For example,
ACC-\d{6} describes the prefix ACC- followed by six digits. Guardrails checks that your pattern is valid, specific enough not to match empty text, and fast enough to run on messages.Change or remove a pattern
- Edit: Open a pattern’s row to change its name or regular expression. Its category is fixed; to use another category, add a new pattern.
- Turn off: Set its scope to Off. The pattern remains saved and uses one of your five slots, so you can turn it back on later.
- Delete: Use the row’s delete action and confirm. Deletion cannot be undone; agents may see matching values again if no other protection catches them.
If a pattern cannot be saved
Related
Data Protection
Learn how CloudThinker handles detected secrets and personal identifiers
Security & Authentication
Manage sign-in security and access roles