Your team is using Claude, ChatGPT, Gemini, or Grok. Without governance, one compromised connection, one tired engineer, one angry customer can break compliance or lose data. Guardrails makes it explicit: what this AI can access, what it's allowed to do, and how we prove it followed the rules. 45-minute workflow. Policy templates. Works for startups and enterprises. Free. Open source.
Status: Phase 1 — live Launch: September 2026 Schema v1.0 — stable ontology License: MIT
GitHub stars0
GitHub forks0
Open issues0
Live sinceSept 10, 2026
You don't need a security team, a finished policy, or a complete list of every AI tool your company uses. Start with what you actually know — the discovery checklist walks you through the rest, in plain language, in about 10 minutes:
Guardrails doesn't care which AI you use — it cares what it can access and what it's allowed to do. That includes AI you didn't realize you had.
| Where it shows up | Examples | What it's typically used for |
|---|---|---|
| Direct AI tools | Claude, ChatGPT, Gemini, Copilot, Grok, Perplexity | Drafting, analysis, code, research, customer support |
| Embedded in tools you already own | Salesforce Einstein, Microsoft 365 Copilot, Zendesk AI, GitHub Copilot | CRM predictions, meeting summaries, support answers, code suggestions |
| Internally built systems | Custom agents, RAG systems, API calls to Claude or OpenAI | Document review, incident response, forecasting bots |
Six ways this is happening right now, inside companies that never decided to take these risks.
Production database down. Panicked, an engineer asks Claude to fix it. If Claude has standing prod credentials and no boundary exists, a wrong command can corrupt the database — and without an audit trail, nobody can prove whether Claude or the engineer made the call.
Uploads 50 applicant résumés to a personal ChatGPT account to screen candidates faster. If that data includes regulated personal information and there's no data processing agreement in place, that can create a GDPR or CCPA compliance risk.
Pastes unreleased quarter-end projections into Claude to sense-check the forecast. If that counts as material non-public information and it's shared with a third-party service without controls, it can create insider-trading exposure and regulatory liability.
A customer is furious. An AI tool suggests bending policy to resolve it. If the agent accepts that suggestion without authority to grant exceptions, the company can end up honoring a commitment it never approved — and liable for the precedent it sets.
Deployed to handle Sev-1 incidents with production access. During a real incident it attempts an action outside its intended scope. Without technical controls limiting what it can actually do, that can mean the difference between a contained incident and a compromised system.
An AI with access to critical infrastructure is never supposed to modify security settings. If its underlying infrastructure is compromised, that boundary only holds if it's enforced technically, not just assumed — and without audit logging, an operator may not even know it happened.
The AI actor's information access or authority exceeds the controls appropriate to the risk.
AI authority must be explicit, bounded, observable, and proportionate to risk.
What AI systems does your company use? What can they access? What are they allowed to do?
How do we actually enforce those boundaries? In the system itself, not just in policy?
When something happens, can we audit exactly what occurred, who authorized it, and whether controls worked?
Same ladder works for code changes, financial decisions, hiring recommendations, manufacturing operations, critical infrastructure, and everything else.
| Level | Authority | Meaning |
|---|---|---|
| 0 | Observe | Access approved information; no derived action |
| 1 | Analyze | Interpret, classify, summarize, or diagnose |
| 2 | Recommend | Propose a decision or course of action |
| 3 | Prepare | Create an artifact/change that cannot take effect without another actor |
| 4 | Execute Bounded | Perform predefined, reversible actions within explicit constraints |
| 5 | Execute Gated | Perform higher-impact actions only when required conditions/approvals are satisfied |
| 6 | Prohibited | Action is unavailable to the AI actor regardless of instruction |
Source of truth. Every AI system your company uses, every use case, classified.
Human-readable baseline policy document, one section per use case.
What's missing? Prioritized by risk, with fix-by timelines.
How we prove this works: tests, owners, and review cadence.
You don't need a CTO or a security title to use this. You need to be worried about how AI is being used at your company and not know where to start.
The fastest way in. About 10 minutes, no signup, nothing leaves your browser.
Start Discovery →Download the policy template and use it with your own team, your own spreadsheets, your own tools.
Download the templates →Free, open source, and vendor-neutral. Fork it, contribute, or build on it. Implements the spirit of NIST, ISO, and OWASP guidance as company-specific controls.
View on GitHub →