Guardrails: System design
Specifies that untrusted retrieved or user content cannot authorize tools or exfiltrate secrets, that the model follows a documented instruction hierarchy, and that outputs are filtered before privileged side effects.
Selects models by declared capability, data-handling policy, and cost budget with explicit forbidden fallback paths so sensitive or high-assurance requests never downgrade to disallowed tiers silently.