Skip to content

Security Custodian Guide ​

Security custodians protect sensitive data and ensure compliance.

Main responsibilities ​

  • Configure security checks
  • Define compliance rules
  • Review audit logs and alerts
  • Review execution governance and sanitization evidence
  • Review access exposure for users and API keys
  1. Enable prompt injection detection.
  2. Configure compliance standards for your industry.
  3. Review security reports regularly.

Blacklist violation reports ​

Security custodians can review and manage chat blacklist violations:

  1. Open Admin → Chat Blacklists.
  2. Use the Blacklist Violation Reports panel to select a date range.
  3. Download a CSV report, archive (download + delete), or delete older records.

Security governance and access review ​

Security custodians should also use the dedicated security governance and access review screens.

Use them to review:

  • geofence denials, policy denials, supervised holds, and fallback events
  • sanitization trigger, mode, profiles, entity counts, and restore status
  • policy change history and blast radius
  • dormant privileged users
  • broad or stale API keys
  • which users can execute prompts or export data

Use the drill-down links from governance instead of starting every investigation from scratch:

  • policy changes open the audit log with the affected routing policy and the same date window already applied
  • sanitization evidence opens the prompt-log explorer with matching provider, policy, project, geo bucket, and timeframe filters
  • execution governance events open the most relevant audit or prompt-log view for that event type
  • anomaly alerts open preset-aware investigation views with short interpretation guidance so custodians can understand the slice before reading raw rows

The routing policy review flow also includes a structured diff viewer so you can inspect what changed without parsing raw JSON manually.

The access review screen complements this by linking dormant privileged users, export-heavy users, and broad API keys directly into the supporting audit or prompt-log evidence for the last review window.

Protection Findings is also usable as an investigation surface now, not just a list. Security custodians can filter by severity, provider, status, user, and date range, then jump from a finding into matching prompt or audit evidence.

The governance views also now surface richer monitoring detail:

  • execution governance counters for blocked, fallback, supervised, export, and policy-change activity
  • sanitization counters for automatic, manual, skipped, restore-failure, and provider-shielded runs
  • charted views for policy coverage, governed execution flow, and top risky actors
  • provider-boundary trend lines plus fallback rows that surface related deny signals when those were recorded nearby in audit data
  • anomaly cards with direct investigation links into prompt or audit evidence
  • anomaly reporting visuals that summarize alert categories and severity for the active window
  • provider-health backfill for local or existing deployments where drift analytics need to be derived from stored prompt history

Learn more ​