Core policy controls
- Model and tool access: Allow, monitor, or block specific AI services
- Content filtering: Define prohibited content categories and actions
- On-device redaction: Mask configured sensitive fields before data is sent
- Exceptions: Assign scoped policy overrides for approved roles or groups
Recommended policy rollout
Enable redaction for sensitive data types
Start with the data classes that matter most for customer risk posture.
Apply targeted blocks
Restrict only high-risk actions first, then expand based on evidence from
policy events.

