Draft a reply to [CUSTOMER] at [EMAIL] about account [ACCOUNT].
AI guardrails
for employees.
Apply your data policy as people share supported prompts and files with AI.
Customer support example: identified details are replaced in the draft.
The employee experience
A clear reason. A clear next step.
For supported prompts and files, show employees why a policy applies and what they can do next.
Prohibited submissions stay blocked.
How policy responses work
A relevant response
Apply the policy to the information being shared, including a configured block or redaction where supported.
A clear boundary
A person can revise a prohibited request or use the organisation's approved process. The prohibited submission stays blocked.
Something to learn from
Use available policy evidence to review repeated issues and improve the policy and employee guidance.

Draft a reply to [CUSTOMER] about account [ACCOUNT].
Roll out with a clear scope
Start with the work your team actually does.
Match the control to the tool, input and device. Test a harmless example before expanding.
See covered AI use
Deploy the relevant client and review the AI activity it observes. An AI-tool catalogue alone does not show your employees' use.
Explore discoveryApply your data policy
Confirm supported prompt and file actions in the actual browser or native app, then test allowed and prohibited inputs.
Review coverageReview the evidence
Check the recorded response, retention and access. Use the result to improve policy without equating usage with productivity.
Understand event evidenceA useful distinction
Protecting people’s AI use. Reviewing an agent’s actions.
Employee guardrails check how a person uses AI, such as sharing a document or submitting a prompt.
Human oversight puts a person at a decision point, such as approving an agent's external action. It needs its own review and enforcement process.
Explore agent oversightCompliance and standards
Connect controls to compliance.
See how a practical control contributes to a specific review.
A guardrail supports a control. Compliance also depends on the organisation, its processes, agreements and the full system in scope.
Patient information
HIPAA and employee AI use
Connect supported data protection and recorded policy events to your PHI review. Verify agreements, permitted use and the remaining information.
Questions
Your questions, answered.
What are AI guardrails for employees?
Are employee guardrails the same as human-in-the-loop approval?
Does the policy apply to every AI app on every device?
What can our security team review?
Does redacting a patient note make it HIPAA de-identified?
Bring a real AI use case.
Map the data, policy and supported coverage with our team.