Skip to main content

Custom detections

Add your own detections to an app when the built-in guardrail categories do not describe what you need caught, such as an internal project codename, a customer ID format or competitor mentions.

Add one to an app​

Custom detections are defined per app. Open the app from Settings > AI Gateway > LLM Gateway and choose any Configure option to open the app workspace's Settings tab, then select Custom Detections under Protection.

Detection types​

TypeHow it matchesUse it for
Precision (regex)Deterministic regex matching, evaluated at the gateway on every call.Identifiers with a fixed shape: employee IDs, ticket numbers, internal hostnames.
IntentSemantic matching against a described intent, steered by examples.Topics and phrasing that no regex can capture: competitor comparisons, requests for legal advice.

Fields​

FieldApplies toNotes
Detection enabledBothSwitch the detection off without deleting it.
Detection IDBothReuse an existing ID to update that detection.
Display nameBothShown in the console.
Code nameBothStable machine name reported with findings.
Positive regexesPrecisionComma-separated regexes that should match.
Negative regexesPrecisionComma-separated regexes that must not match. A match here suppresses the finding.
Intent descriptionIntentPlain-language description of what to detect.
Positive examples / Negative examplesIntentComma-separated prompts that should and should not match.

Create a detection​

  1. Choose Precision (regex) or Intent.
  2. Enter a new Detection ID, a Display name and a Code name.
  3. Add the regexes, or the intent description and examples.
  4. Select Save detection.

Save detection applies the change immediately. It does not wait for the app's Save settings button, and it is recorded in the app's Audit Log.

Writing good examples

For intents, add negative examples that are close to the positive ones. A detection for "competitor pricing questions" needs negatives such as "what is our own pricing?" to stay precise.

Going further with the Policy Engine​

Custom detections stay editable in app settings when the Policy Engine is on; they do not freeze (see What happens to classic settings). In the Data & Adversarial Risks card, they appear under the Custom group of the data type picker, so a data rule can give them their own action, threshold, stage and scope. For example, block a project codename only for one Smart group, or only on requests to one provider. See Security guardrails.

Tenant-wide detectors and the shared detection library are managed in the console's Detection Models. See Custom detections and library.