Turn findings into detections
Agentic and Model Red Teaming reports do more than list what broke. The Remediation section of each report suggests controls that would stop the same attacks in production. This page explains where each suggestion goes.
What the report suggests
Some runs also suggest a Token Limit control, for example to cap oversized extraction requests.
Add a suggested detection
- In the report, open Remediation and copy the patterns from a custom detection suggestion.
- Go to Govern › Detection Models, open the Custom view, and create a detection with those patterns (or describe it in the Detection Model builder). Test it before saving.
- Use the detection in a control on the Policy Engine for the surface that reaches the target, with the action the report suggested.
Verify the fix
Click Apply & verify with the guardrail in the report to re-run the assessment with Quilr's guardrail in front of the target and compare before/after grades. After you change the prompt or add detections, re-run the assessment (or let a schedule do it) and close the finding in the findings tracker.
These suggestions come from Agentic and Model Red Teaming reports. For LLM Intelligence Assessment runs, use the Guardian counterfactual (residual failures and potential over-blocks) to tune Guardian policy instead. See Reading a report.