Appearance
Security Custodian Guide
Security custodians protect sensitive data and ensure compliance.
Main responsibilities
- Configure security checks
- Define compliance rules
- Review audit logs and alerts
- Review execution governance and sanitization evidence
- Review access exposure for users and API keys
Recommended setup
- Enable prompt injection detection.
- Configure compliance standards for your industry.
- Review security reports regularly.
Blacklist violation reports
Security custodians can review and manage chat blacklist violations:
- Open Admin → Chat Blacklists.
- Use the Blacklist Violation Reports panel to select a date range.
- Download a CSV report, archive (download + delete), or delete older records.
Security governance and access review
Security custodians should also use the dedicated security governance and access review screens.
Use them to review:
- geofence denials, policy denials, supervised holds, and fallback events
- sanitization trigger, mode, profiles, entity counts, and restore status
- policy change history and blast radius
- dormant privileged users
- broad or stale API keys
- which users can execute prompts or export data
Use the drill-down links from governance instead of starting every investigation from scratch:
- policy changes open the audit log with the affected routing policy and the same date window already applied
- sanitization evidence opens the prompt-log explorer with matching provider, policy, project, geo bucket, and timeframe filters
- execution governance events open the most relevant audit or prompt-log view for that event type
- anomaly alerts open preset-aware investigation views with short interpretation guidance so custodians can understand the slice before reading raw rows
The routing policy review flow also includes a structured diff viewer so you can inspect what changed without parsing raw JSON manually.
The access review screen complements this by linking dormant privileged users, export-heavy users, and broad API keys directly into the supporting audit or prompt-log evidence for the last review window.
Protection Findings is also usable as an investigation surface now, not just a list. Security custodians can filter by severity, provider, status, user, and date range, then jump from a finding into matching prompt or audit evidence.
The governance views also now surface richer monitoring detail:
- execution governance counters for blocked, fallback, supervised, export, and policy-change activity
- sanitization counters for automatic, manual, skipped, restore-failure, and provider-shielded runs
- charted views for policy coverage, governed execution flow, and top risky actors
- provider-boundary trend lines plus fallback rows that surface related deny signals when those were recorded nearby in audit data
- anomaly cards with direct investigation links into prompt or audit evidence
- anomaly reporting visuals that summarize alert categories and severity for the active window
- provider-health backfill for local or existing deployments where drift analytics need to be derived from stored prompt history
