<POST> ConfigureApp API
The payload below defines the configurable policy that a user can apply to validate the corresponding prompt/ response. To apply the policy:
- Copy and replace the appropriate policy object in the request JSON payload as shown below.
- Select the correct policy configuration schema based on execution Mode "block" or "audit" also depending on the environment where the container is deployed "cpu" or "gpu"
- "Audit Mode"works with out LLM Orchestration and "Block Mode" works with LLM Orchestration .
Note: This policy is fully customizable and can be modified to reflect the desired behavior of your application or integration.
{
"config_language": "en",
"config_llm": "Mistral",
"image_analysis_type": "",
"input_config": {
"JSON": {
"enabled": false
},
"Block Competitor": {
"comparison": "contains",
"value": ""
},
"Block Substring": {
"comparison": "contains",
"value": ""
},
"Allowed List": {
"comparison": "contains",
"value": ""
},
"Regex": {
"value": ""
},
"URL Detection": {
"enabled": false
},
"Code Detection": {
"enabled": false
},
"Ban Topic": {
"value": "",
"threshold": "high",
"custom_threshold": 0
},
"BCI Detection": {
"enabled": false,
"custom_model_available": false,
"mode": "default",
"threshold": "High",
"custom_threshold": 0
},
"Toxicity": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0.80
},
"Generic Harm": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"PII Detection": {
"enabled": false,
"redaction": false
},
"Special PII Detection": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Prompt Injection / Jailbreaks": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Secrets": {
"enabled": false
},
"Not Safe For Work": {
"enabled": false,
"threshold": "low",
"custom_threshold": 0
},
"Gender Sensitive": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Token Limit": {
"value": "4096"
},
"Input Rate Limiter": {
"value": "10"
},
"Invisible Text": {
"enabled": false
},
"Medical Safety Detection": {
"enabled": false,
"threshold": "low",
"custom_threshold": 0.85
}
},
"output_config": {
"JSON": {
"enabled": false
},
"Block Competitor": {
"comparison": "contains",
"value": ""
},
"Block Substring": {
"comparison": "contains",
"value": ""
},
"Allowed List": {
"comparison": "contains",
"value": ""
},
"Blocked List": {
"comparison": "contains",
"value": ""
},
"Regex": {
"value": ""
},
"URL Detection": {
"enabled": false
},
"Code Detection": {
"enabled": false
},
"No LLM Output": {
"enabled": false
},
"Malicious URL Detection": {
"enabled": false
},
"URL Reachability": {
"enabled": false
},
"Ban Topic": {
"value": "",
"threshold": "High",
"custom_threshold": 0
},
"BCI Detection": {
"enabled": false,
"custom_model_available": false,
"mode": "default",
"threshold": "High",
"custom_threshold": 0
},
"Toxicity": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Generic Harm": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Sentiment": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"PII Detection": {
"enabled": false,
"redaction": false
},
"Special PII Detection": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Secrets": {
"enabled": false
},
"Not Safe For Work": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Gender Sensitive": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},
"Medical Safety Detection": {
"enabled": false,
"threshold": "High",
"custom_threshold": 0
},,
"Contextual Groundedness": {"enabled": true},
"Answer Relevance": {"enabled": true}
}
}
🛡️ Confidence Thresholds in Guardian :
Guardian uses a confidence thresholds to decide when to flag a user query / model response as potentially unsafe/risk. These thresholds control how cautious or relaxed the system is when making that decision.You can choose between four modes: High, Medium, Low(default), and Custom — each offering a different balance between precision and coverage.
🔵 High Threshold:
In this mode, Guardian will only flag when it is very confident that a user query / response violates a defined boundary.This results in a low false positive rate — meaning very few things will be flagged incorrectly. However, it may miss some actual violation that don’t meet the high confidence level. This setting is ideal when you want to avoid unnecessary disruptions or over-flagging, especially in low-risk.
🟡 Medium Threshold:
With the medium threshold, Guardian takes a balanced approach. It flags content when it's reasonably confident that there may be a potential policy issue or risk. You may see a moderate false positive rate, but it also reduces the chances of missing real violations. This is a good default choice for most general-purpose use cases where you want a balance between accuracy and coverage.
🔴 Low Threshold :
The low threshold setting is the most sensitive. Guardian will flag responses even if it has only a moderate level of confidence that something might violate policy. This ensures that almost no actual issues go undetected, but it also increases the false positive rate — meaning more content might be flagged unnecessarily. It’s best suited for high-sensitivity environments where missing a potential violation is riskier than flagging extra content.
⚙️ Custom Threshold:
If your use case requires more precise control, you can set a custom threshold between 0 and 1. Lower values make Guardian more aggressive in flagging (higher sensitivity), while higher values make it more conservative (flagging less frequently). This mode is ideal when you have specific business rules, risk tolerance levels, or workflows that need fine-tuning.
By adjusting the confidence threshold, you’re effectively choosing how cautious Guardian should be — whether it should only flag highly certain violations or proactively surface anything that might require attention.
import requests
import json
url = "{guardian_url}/configureApp/{app_name}"
# please copy the request payload according to given mode and device type
payload = {# <<Enter Payload Data>>}
headers = {
'Accept': 'application/json',
'Content-Type': 'application/json'
}
response = requests.request("POST", url, headers=headers, data=json.dumps(payload))
print(response.text)
Request Body Definitions
The table below provides a detailed breakdown of all fields included in the API request body. It describes each field's purpose, type, and possible values to help you configure the API effectively with examples.
Field | Type | Description |
|---|---|---|
config_language | String | Specifies the languages that the system supports for user interaction. Can be English (default value) or English & Korean both. by default "en", possible values "en,ko" |
config_llm | String | Defines the configured Language Model (LLM) to be used.
|
image_analysis_type | String | Supported Image Analysis types like OCR or Content Moderation.
|
Theme | Policy | Description | Key | Type | Possible Values |
|---|---|---|---|---|---|
Additional Checks | JSON | Ensures correctness and validates JSON format | enabled | Boolean | true / false |
Content Access Control | Block Competitor | Blocks mentions of competitors | value | String | comma-separated string |
| | | comparison | String | "exact_match" / "contains" |
Content Access Control | Block Substring | Blocks specific strings of text | value | String | comma-separated string |
| | | comparison | String | "exact_match" / "contains" |
Content Access Control | Ban Topic | Blocks entire topics of discussion | value | String | comma-separated string |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Content Access Control | Allowed List | Permits only approved content | value | String | comma-separated string |
| | | comparison | String | "exact_match" / "contains" |
Content Access Control | Blocked List | Prevents output of certain block listed content | value | String | comma-separated string |
| | | comparison | String | "exact_match" / "contains" |
Content Analysis | Regex | Uses patterns to match text/alphanumeric for filtering | value | String | single regex pattern |
Content Safety | URL Detection | Identifies URLs in prompt | enabled | Boolean | true/false |
Security Measures | Code Detection | Identifies programming code in text (C, C++, HTML, Bash, JAVA, JavaScript, Python, C#, JSON) | enabled | Boolean | true/false |
Content Safety | Toxicity | Filters toxic and harmful language in input or in prompt's response | enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Content Safety | Generic Harm | Blocks swear words and vulgar language (supports English language) | enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float
| If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Privacy Protection | PII Detection | Detects personal identifiable information (e.g., Full name, email address, phone number) | enabled | Boolean | true/false |
| | | redaction | Boolean | true/false |
Content Validation | No LLM Ouput | Underlying LLM refuses to provide an answer | enabled | Boolean | true/false |
Content Validation | Contextual Groundedness | Checks if the response aligns with the provided Context | enabled | Boolean | true/false |
Content Validation | Answer Relevance | Checks the relevance between the provided query and response | enabled | Boolean | true/false |
Security Measures | Special PII Detection | Detects specialized personal information | enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Content Safety | Sentiment | Analyzes the sentiment of AI responses (positive, negative, or neutral) | enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Security Measures | Prompt Injection / Jailbreaks | Detects attempts to manipulate the AI | enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Security Measures | Secrets | Detects and redacts sensitive information (AWS Secrets, Git Secrets, DB Secrets) | enabled | Boolean | true/false |
Security Measures | Malicious URL Detection | Scans for harmful URLs in output | enabled | Boolean | true/false |
Additional Checks | URL Reachability | Checks if URLs in output are accessible | enabled | Boolean | true/false |
Content Safety | Not Safe For Work | Filters sexually explicit or inappropriate material | enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Content Safety
| Medical Safety Detection | Detects Medically Unsafe information
| enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Content Safety
| Gender Sensitive | Identifies Gender discrimination, bias, and stereotype
| enabled | Boolean | true/false |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
Security Integrity Checks
| Invisible Text | Identifies hidden text within inputs
| enabled | Boolean | true/false |
Usage Management
| Input Rate Limiter | Limits the rate of input to the system
| value | Integer | Integer |
Usage Management
| Token Limit | Sets limits on token usage in requests
| value | Integer | Integer (max 4096) |
Privacy Protection
| BCI Detection | Detects business confidential information
| enabled | Boolean | true/false |
| | | custom_model_available | Boolean | by default false, once custom model will upload then can set as true |
| | | mode | String | "default" / "custom" |
| | | threshold | String | "Low" / "Medium" / "High" / "Custom" |
| | | custom_threshold | Float | If threshold is set to "custom", provide a custom_threshold value in the range of Float (0.0 to 1.0), default is 0.0 |
🧠 Hallucination Detection:
- Hallucination detection can be checked by enabling the policies like: Contextual Groundedness and Answer Relevance . These checks enable precise validation of model responses against a supplied context or prompt, prompt or model's response, helping ensure factual consistency and response integrity.
- This capability is available only on GPU-enabled environments.
Feature Overview:
- Contextual Groundedness Check Verifies that the model’s response is logically and semantically grounded in the provided context (context and response are required fields for audit mode and only context is required field for block mode). It identifies instances where the response introduces unsupported or fabricated information.
- Answer Relevance Check Assesses whether the response meaningfully answers the original user query (response is required fields for audit mode and in block mode response will be taken care by querying the respective llm)and stays within the scope of the provided question.
⚙️ How to Use:
To activate hallucination checks, structure your payload using the following tags:
1. Formatting for Context:
2. Formatting for LLM/Model response:
3. Formatting for Prompt:
🚫 Do not include any tags in the prompt. Only the context and response must be tagged.
📘 Examples:
Audit Mode:
Block Mode:
In Block Mode, only the context tag is required.