Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    AI Gateway
    Configuration
    AI Gateway Policies
    AI Guardrails

    AI Guardrails

    Create New Guardrails Group

    To create a new Guardrails policy group, follow the steps below.

    1. Log in to the Netskope tenant UI and go to Policies > AI Gateway.

    2. In the AI Gateway page, click the AI Guardrails tab and click New Policy Group.

    3. In the New Policy Group page, enter a name for the group in the Group Name parameter.

    4. Choose the position of the new policy group by selecting a group from the Before policy group or After policy group lists respectively.

    5. Click Create.

    Create New Guardrails Policy

    To create a new Security Guardrails policy, follow the steps below.

    1. Log in to the Netskope tenant UI and go to Policies > AI Gateway.

    2. In the AI Gateway page, click the AI Guardrails tab and click New Policy.

    3. In the New AI Guardrails Policy page, create a policy that matches one (or more) of the following criteria :

      • Token Group
      • AI Provider and Model
      • Activity – Prompt and Response
    4. From the Add Exclusion Criteria Group list, choose the token group that you want to exclude from the match criteria. For example, you want to match against all openai AI Providers, but not for traffic with token group admin. In that case you can specify this exclusion criteria by selecting Add Exclusion Criteria Group, choose Token Group and select the required token group from the drop-down.

    5. Under Profile, select AI Guardrails from the list.

    6. From the Action parameter, select the enforcement action to be applied when traffic matches your specified criteria:

      • Monitor: Logs the traffic activity for visibility and allows the request to proceed to the subsequent policy.
      • Block: Immediately terminates the connection and drops the traffic.
      • Replace: Intercepts the response and replaces the content with a custom, administrator-defined message.
    7. Specify the name of the policy, description, the policy group that it should be part of, and the position of the policy within that policy group.

    8. Click Save and apply changes to your creation.

    In this Topic
    • AI Guardrails