Skip to main content

Overview

The Prisma AIRS AI Gateway enables organisation owners to enforce request guardrails at the organisation level. This feature ensures that all API requests made within the organisation comply with predefined policies, enhancing security, compliance, and governance.

How It Works

Organisation owners can define input and output guardrails in the Organisation Guardrails section. These guardrails are enforced on all API requests made within the organisation, ensuring uniform policy enforcement across all users and applications.
  • Input Guardrails: Define checks and constraints for incoming LLM requests.
  • Output Guardrails: Ensure LLM responses align with organisational policies.
The guardrails available here are the same as those found in the Guardrails section of the Prisma AIRS AI Gateway. Multiple providers are supported for setting up guardrails. For a detailed list of supported providers and configurations

Guardrials Docs

Learn about the different Guardrails you can set up in the AI Gateway

Configuration

Setting Up Guardrails Requirements

  1. Head to Admin Settings on Strata Cloud Manager
  2. Navigate to the Organisation Guardrails section
  3. Add your Input and/or Output Guardrails
  4. Save your changes
Once configured, these guardrails will be enforced on all API requests across the organisation.

Excluding Workspaces

Some workspaces — an internal evaluation sandbox, for example — may need to run without the organisation’s default guardrails. You can exempt them individually while every other workspace stays covered. Exclusions are managed per guardrail direction through the Admin API, and require an organisation service API key with the organisation_exclusions.update and organisation_exclusions.list scopes.
Workspace exclusions are currently available via the API only. Support for managing them from Strata Cloud Manager is coming shortly.
Use /workspace-exclusions/output-guardrails for output guardrails, and set excluded to false to bring a workspace back under enforcement. Pass override_existing: true to replace the current exclusion list rather than merge into it. The matching GET endpoint returns the workspaces currently excluded.
Best Practices
  • Clearly communicate guardrail requirements to all developers in your organisation.
  • Maintain internal documentation on your guardrail policies to ensure consistency.
Last modified on September 15, 2026