Skip to main content
Step 2 of the agent wizard, and editable afterwards from the agent’s page.

What you can set

PII handling

Three modes:
  • Allow — the agent handles personal data normally.
  • Mask — it never repeats personal data back in a reply.
  • Block — it refuses to handle it and hands off to a human.
PII handling is enforced as an instruction to the model, not as a filter applied to the reply after it is written. It is a strong instruction, not a guarantee. If you are handling data where a leak would be a regulatory problem, do not rely on this alone — keep that conversation with a human.
That caveat applies in spirit to every guardrail here: they steer the model reliably, but they are not a hard filter. Anything that absolutely must not be said is better handled by not giving the agent the information in the first place.

Writing rules that work

Be specific and positive about the alternative. “Never discuss pricing” leaves the agent stuck. “Never quote a price — say a member of the team will confirm current pricing” gives it somewhere to go. Put genuine hard limits in never-rules, not tone rules. Tone rules shape style; never-rules are treated as absolute. Escalation is a feature, not a failure. An agent that hands over promptly on refunds and complaints is more valuable than one that tries everything. Make the escalation triggers generous.

Changes need a re-compile

Editing guardrails does not take effect until the agent is compiled again. Save, then Review & Compile.