Skip to content

Platform

Guardrails, Security & Governance

A platform that can act needs to know what it must not do. Guardrails, identity, workspace separation, and audit are evaluated in the runtime on every request - so the answer to “what stopped it?” is a policy decision on a trace, not a hopeful sentence in a prompt.

Bhogar workspace Guardrails page listing active guardrails such as Token Limit, Per-Request Cost Cap, PII Protection, Content Moderation, and Healthcare PHI Redaction.

How it works

Setting up governance

Set up once, enforce continuously, review with real data. Governance work should shrink as coverage grows, not scale with it.

Guardrails, Security & GovernanceProcess diagram

Establish identity

Federate sign-in, enforce MFA, and define the roles and workspaces that mirror how your organization is structured.

identity + role model

Capabilities

Governance controls

Governance is not a settings page. It spans identity, workspace separation, retrieval, action authority, spend, and evidence - and all of it has to hold at runtime.

Runtime guardrail policies

Input and output policies are evaluated server-side on every request - content rules, prompt-injection screening, grounding requirements, and refusal behaviour.

Portal - Observe → Governance

PII detection and handling

Detect sensitive fields and choose per data class whether to redact, mask, or block - before the content reaches a model or a log.

redact - mask - block

RBAC across every surface

One permission model governs retrieval, tool calls, mutations, and reporting. Roles and module access are evaluated on the same predicate everywhere.

roles - module access - workspace scope

Multi-tenant isolation

companies and workspaces separate data and execution at the platform level, so no agent, index, or trace crosses a tenant boundary.

org + workspace primitives

Enterprise identity

SSO through SAML and OIDC, Microsoft Entra sign-in, MFA and WebAuthn, device trust, and session controls administered centrally.

SAML - OIDC - MFA - WebAuthn

Spend and rate authority

Budget ceilings, per-route rate limits, and tool-level quotas mean an unattended agent cannot run up an unbounded bill.

budgets - quotas - rate limits

Approval workflows

Sensitive actions require named human sign-off, with the request, its evidence, and the intended action presented to the approver.

human-in-the-loop authority

Audit trail

Policy verdicts, approvals, configuration changes, and access events are retained with the policy version in force at the time.

who - what - when - under which policy

Compliance posture

Governance dashboards, compliance findings, and an auditor view give reviewers evidence without handing them production access.

findings - auditor portal

Design decisions

Our approach to AI governance

These are the choices that decide whether controls survive contact with a determined user or a scaled rollout.

Policy is server-side, always
Guardrails that live in a system prompt are suggestions. Bhogar evaluates policy in the runtime, so the same rules apply whether a request arrives from the Portal, an embedded widget, the API, or a scheduled job.
Permissions are enforced during retrieval
Filtering after generation is too late - the model has already read the content. Access control is applied while retrieving, so restricted material never enters a prompt in the first place.
Writes never fail open
If an authorization check cannot be resolved, a mutating action is refused rather than allowed. Read paths degrade gracefully; anything that changes state does not.
Authority is granted per tool
An agent’s ability to act is the union of the tools it was granted, each with its own scope and limits. Widening authority is an explicit configuration change, not an emergent behaviour.
Human approval is a state, not an email
Approvals pause a durable run, present the evidence, and record the decision. That is auditable in a way that an out-of-band message thread never is.
Explainability is the point of audit
Retaining the policy version, the retrieved sources, and the verdict means you can answer “why did the system do that?” months later - which is what regulators, auditors, and incident reviews actually ask.

Procurement

Resources for security and procurement reviews

Published references for security and legal review - plus a route to a human when a questionnaire needs answering.

Governance evidence exists by default, so review is a read rather than a build.

Time to security approval

policy documentation, audit trail, compliance findings

Blocked and redacted events show controls working instead of hoping they are.

Policy violation rate

guardrail verdict counts by policy and route

Ceilings and quotas convert a runaway-cost risk into a bounded one.

Unbudgeted spend

budget guard events and enforced limits

Faster sign-off when approvers get the evidence with the request.

Approval turnaround

approval wait time per workflow

Answering “what ran, under which policy” takes minutes rather than a project.

Audit response time

retained decisions with policy version

Governance that holds is what allows expansion beyond the pilot team.

Rollout confidence

workspaces enabled without new control work

FAQ

Frequently asked questions

Can a user prompt their way around a guardrail?
No. Policy is evaluated in the runtime rather than described to the model, so wording cannot widen permissions, unlock a tool the agent was not granted, or bypass a PII rule. The same checks apply to API and scheduled traffic, not only the chat surface.
How is PII handled?
Sensitive fields are detected and handled per data class before content reaches a model or persistent log - redacted, masked, or blocked according to policy. Trace payload retention is configurable so audit evidence does not become a new data-exposure surface.
What identity and access controls are supported?
SSO via SAML and OIDC, Microsoft Entra sign-in, MFA and WebAuthn, device trust, session management, and role-based access with module-level packs. companies and workspaces provide the workspace separation boundary that all of it is evaluated inside.
What compliance documentation is available?
The trust centre covers our security posture, and procurement resources - GDPR, SOC 2, DPA, and SLA pages - are published for review. Enterprise engagements include security questionnaires, a DPA, and where required a review of deployment topology.
Can we deploy inside our own boundary?
Yes. Enterprise plans support deployment into your own cloud account with private networking, plus bring-your-own models and provider keys, for data that cannot leave a defined perimeter.

See Bhogar on your own data

Book a 45-minute working session. We connect one of your sources, build one agent, run one governed workflow, and review the trace together.