Guardrails are the checks between a request and any action: the request is screened, the plan is limited to the skill’s allowed tools, your policy decides what may run, and risky steps wait for the employee’s approval.
Rejects anything outside IT support and any attempt to manipulate the agent, including prompt injection.
Off-topic requests, jailbreak attempts, instructions smuggled inside a request.
G2 - Plan
Checks the plan against the skill: every step must use one of its allowed tools, and diagnostics must run before fixes. A plan that fails is rewritten, never part-run.
Tool outside the skill’s allowlist, corrective actions before diagnosis, skipped prerequisites, risk outside boundary.
G3 - Policy
Checks the approved plan against your central policy: which actions need admin approval, what’s forbidden, for whom.
Anything your organization has ruled out.
G4 - Execution
Risky steps show exactly what would change and wait for the employee to approve or decline. Only code-reviewed tools run — the AI never writes commands or scripts — and every input, result and decision is recorded.