Settings → AI Settings → AI Guardrails
Per-resource-type kill switch for the AI session-injection allowlist. The allowlist is the gate that decides which commands the AI is allowed to type into a live operator session — show / ping / traceroute for Cisco devices, AWS CLI read verbs for AWS accounts, read-only kubectl verbs for Kubernetes clusters, and so on. This screen lets you turn that gate on or off per resource type.
The tab is split in two columns. The left column lists every registered resource type with a green on / red off badge showing the current state; the right column shows a description of what the guardrail is blocking, plus the toggle.
What you can do
- Pick a resource type on the left and read what its allowlist actually permits today.
- Toggle the guardrail on or off — the change is saved immediately.
- Reset the guardrail for a single type back to its default (allowlist enforced).
The default for every type is on (allowlist enforced). Disabling a guardrail does not remove the other safety layers: the AI is still rate-limited (5 commands per 10 seconds), still bound to the calling user’s own session, and still restricted to session-assistance agents only.
What each guardrail covers
| Resource type | What “on” means |
|---|---|
| Cisco IOS / IOS-XE / IOS-XE SD-WAN / NX-OS / Infoblox NIOS | Only read-only show / ping / traceroute |
| Cisco ISE / vBond / vManage / vSmart | Only read-only show / ping / traceroute — disabling exposes deployment-affecting operations (application stop/configure, reload, fabric-wide policy changes) |
| Nokia SR Linux | Only read-only info / show / ping / traceroute |
| PAN-OS | Only read-only show / test / ping |
| Linux | Read-only diagnostic commands (cat, ls, ip, ss, ping, traceroute, dig, df, free, uptime, ps, netstat, journalctl, …) |
| Windows | Read-only diagnostic commands (ipconfig, netstat, ping, tracert, systeminfo, …) plus read-only PowerShell verbs (Get-, Measure-, Select-, Sort-, Where-, Format-) |
| Databases (PostgreSQL, MySQL, MariaDB, SQL Server, ClickHouse) | Read-only SQL only — SELECT, SHOW, WITH, EXPLAIN and safe introspection; writes, DDL, and host- or file-touching commands are denied |
| AWS account | AWS CLI read verbs (describe, list, get, search, lookup) |
| Azure subscription | Azure CLI read verbs (show, list, get, plus account show, resource list) |
| Kubernetes cluster | Read-only kubectl verbs (get, describe, logs, top, version, …); state mutators, streaming flags (-f, -w), and exec / cp / attach are blocked |
| Generic SSH | Only the read-mode custom commands you have defined for the type on the Commands tab — nothing if you have defined none |
| Generic RDP / VNC / Web | These graphical session types do not support AI command injection at all, so the toggle has no effect |
The exact wording for each type is shown in the right column when you select it — treat that as the authoritative description for your installed version.
Common tasks
Disable the allowlist for one type
- Click the type in the left column.
- Read the description so you know what you’re removing.
- Flip the green toggle. A toast confirms the save.
Re-enable / reset to default
Flip the toggle back on, or click the orange refresh icon next to it and confirm the Reset Guardrail dialog. Both restore the default behavior (allowlist enforced).
Audit the change
Every toggle emits a log entry (ai_guardrail_updated; resets emit ai_guardrail_reset) including the resource type, the new state, and the timestamp. There is no separate AI-Guardrails audit table — guardrail changes share the standard application log.
Caveats
- Disabling a type’s guardrail lets the AI inject anything on that type — including write commands. This is intended for power users who trust their agents and have other compensating controls. Use with care.
- For
generic_ssh, the guardrail draws its allowlist from your own custom commands: with the gate on, the AI may inject only the read-mode custom commands defined for the type (and cannot inject anything if none are defined); with the gate off, every command goes through. Define custom commands on the Commands tab.
Permissions
- View the tab:
app.ai.read. - Toggle or reset a guardrail:
app.ai.write.