Guardrails: System design
Specifies that untrusted retrieved or user content cannot authorize tools or exfiltrate secrets, that the model follows a documented instruction hierarchy, and that outputs are filtered before privileged side effects.
Referencev0.1.0NOASSERTION
Published Sep 12, 2026