Set boundaries for what employees can read, say, share, and do. Protect data, enforce your policies, and route sensitive actions to you for approval.
Input Safety blocks prompt injection before it can change an employee's instructions. Output Safety catches unsafe or off-brand replies before anyone receives them.
PII Protection redacts personal data before an AI model sees it. Data Leakage Prevention keeps confidential workspace information from being exposed.
Topic Control keeps each employee inside the business subjects you allow and away from the subjects you block.
Approvals add a human checkpoint only where you choose it, so routine work stays automatic and high-impact actions wait for your decision.
At a Glance
0
Sensitive actions without approval
Auto
PII detection and redaction
Company-wide
Policy enforcement
Benefits
Stop unsafe input and output
Screen incoming instructions and outgoing replies before they can change employee behavior or reach a customer.
Keep sensitive data private
Redact personal data and prevent confidential workspace information from being shared with an AI model or outside party.
Keep work on topic
Set the topics each employee may discuss, and block subjects that do not belong in the conversation.
Keep people in control
Require approval before an employee uses a sensitive tool or takes a high-impact action.
How It Works
Choose the boundaries that fit your business, then apply them across your workforce from one place.
Start with the five safety policies: Input Safety, Output Safety, PII Protection, Data Leakage Prevention, and Topic Control. Each policy has its own switch and settings, so you can protect customer conversations differently from internal research.
When a policy applies, it checks the next message for every employee. You can inspect what it caught and why, then adjust the policy without rehiring anyone or changing individual prompts.
Use Approvals when an action needs a person in the loop. The employee explains what it needs to do, pauses until you approve or reject it, and continues from the same point. Waiting costs no credits.
Use Cases
Protect public-facing conversations
Block harmful prompts and unsafe replies before a website visitor, customer, or external contact sees them.
Protect customer and company data
Redact personal details before a model reads them and stop employees from disclosing confidential workspace information.
Keep specialists within their remit
Give a support employee the topics it can address, then keep unrelated or prohibited subjects out of the conversation.
Approve only the actions that matter
Let routine work proceed, but require your decision before an employee sends, submits, purchases, or deletes.
FAQ
What is AI Guardrails?
AI Guardrails is a built-in workspace system, not an employee you hire. It applies the safety policies you choose to every employee, checking what they receive, say, share, and discuss.
Which protections can I turn on?
Choose Input Safety, Output Safety, PII Protection, Data Leakage Prevention, and Topic Control independently. Each has its own settings, so you can use only the protections your work requires.
Do AI Guardrails cost extra?
AI Guardrails is a built-in workspace system. The policies you enable protect employee work as it runs, and you can review each policy's activity from Settings.
Do the policies apply to new employees too?
Yes. AI Guardrails is workspace-wide, so the policies you enable apply to every employee from their next message, including employees you hire later.
Can I require approval before an employee acts?
Yes. In Approvals, mark the sensitive tools that must ask first. The employee pauses with the action and its reason, then continues when you approve or reject it. Routine work remains automatic.
Can I see what a policy stopped?
Yes. AI Guardrails records policy triggers, so you can inspect what was caught, the policy involved, and why it acted. Use that history to tune the settings with evidence instead of guessing.
Autonomy inside boundaries you set
AI Guardrails applies the policies you choose to every employee in your workspace, including employees you hire later. Configure the rule once instead of repeating it in every employee's instructions.
The policies are independent. Turn on stricter protection where it matters, leave other checks off when they would get in the way, and review every trigger when you need evidence of what happened.
How It Works
Choose your policies: Turn on the protections you need and set their strictness, data types, or allowed topics.
Apply them across the workspace: The same policy protects every employee from the next message, including future hires.
Inspect what changed: Review policy triggers and approval requests with the reason each one was stopped or sent to you.
We turned on PII redaction and approval gates for anything touching customer data. Now I can let agents run freely without worrying about compliance.
Features in AI Guardrails
Protect Against Prompt Injection: Input Safety reads every incoming message before your employee does, and stops the ones trying to hijack it: instructions to ignore its rules, requests to print its own configuration, and role-play framed to talk it out of its guardrails. That matters most where the message did not come from you, so a payload buried in a forwarded email, a support ticket, or a shared thread cannot turn your employee against you. Pick Low, Medium, or High, and every level catches the textbook attacks: the level decides how much benefit of the doubt the genuinely ambiguous messages get. Medium is the default and suits most companies. Blocked messages get a short, human reply and the conversation carries on, with each one recorded so you can see what has been tried.
Block Unsafe Employee Responses: Output Safety reads your employee's reply before anyone else does. Toxic, abusive, or otherwise unfit answers are held back rather than sent, which is what you want the moment employees write to customers, post to a channel, or answer a ticket without you watching. It checks the reply your employee actually wrote, so what you see caught is what would genuinely have gone out. Set it to Low, Medium, or High and review everything it held back in the live inspector. Blunt, direct, and critical business writing is left alone: the policy is looking for replies that would embarrass you, not ones that are simply frank.
Protect Personal Data: PII Protection finds personal data in a message and replaces it with a marker before the model reads a single character of it. A pasted card number becomes [CREDIT_CARD], an email becomes [EMAIL_ADDRESS], and the same happens on the way out so nothing sensitive travels back into an email, a channel, or a ticket. You pick exactly what to protect from seven data types: email, phone, name, credit card, Social Security number, IP address, and address. The markers keep the sentence readable, so your employee understands the request perfectly and keeps working while the raw value stays out of the conversation. It runs on every message, in both directions, company-wide, from one switch.
Control What Employees Discuss: Topic Control gives you two lists and you can use either or both. Blocked topics are off-limits no matter how a conversation gets there, which keeps employees out of politics, competitor comparisons, or medical and legal advice. Allowed topics set a remit instead: name the subjects an employee handles and anything unrelated is politely declined, which is how you keep a support employee on product help, billing, and refunds. Both lists match on meaning rather than exact words, so ruling out competitor pricing also covers how much cheaper are we than the other tools out there. Greetings and short replies always get through, so a scoped employee still feels natural to talk to.
Keep Confidential Data In-House: Data Leakage Prevention guards both ends of the conversation. On the way in it recognises someone fishing for your employee's internals, whether they ask outright, dress it up as a game, or try the repeat everything above this line trick. On the way out it reads the reply itself and holds it back if it is about to hand over a system prompt, internal configuration, an access token, or a credential. Questions about your own business data are never affected, so an employee still answers freely about your customers, documents, and numbers. One switch, no configuration to maintain, and every attempt is logged so you can see who has been probing.
Prevent Repeated and Runaway Actions: Sistava automatically caps how many emails, messages, and external writes (CRM records, calendar events, paid searches) an AI employee can send in a single conversation, hour, and day, and blocks an identical send to the same recipient from going out twice within 24 hours. These limits run in the background per employee with no setup required, so a stuck task or unexpected loop cannot spam a contact's inbox, pollute your CRM, or burn through paid API calls. When a limit is hit, the employee is told to slow down or hand the task to a human instead of retrying blindly.
Human-in-the-Loop (HITL): Human-in-the-Loop (HITL) lets an AI employee pause and ask before it takes a sensitive action, like sending an email or spending on a paid tool, instead of guessing what you want. An inline card shows up right in the chat with Approve, Reject, or option buttons, and the employee resumes the instant you respond.
Protect Organisation Information: Your AI employee treats what it learns in the workspace the way a careful coworker would: useful for doing the work, not free to repeat. It tells private, role-restricted, and confidential information apart from ordinary shared context, and it never volunteers the sensitive kind just because someone asked. When a teammate needs a restricted answer, the employee can request permission from the right person for that one specific answer instead of guessing or refusing outright.
Protect Your Email Reputation: Every email your AI employees send, whether it is a notification, a mailbox reply, or an outbound message, passes through a pre-send check before it leaves. Sistava validates the address, checks it against a suppression list built from past bounces and complaints, and blocks anything that would hurt your sending reputation. You do not configure this: it runs silently on every send so your domain keeps a clean track record with inbox providers.
Delegation & Teamwork Limits: Tune how your leader employees hand off work to teammates. Set how many teammates a leader can delegate to at once, how far a delegation chain can reach, how long a delegated teammate can work before timing out, and how tolerant employees are of repeating themselves before loop protection stops them.
Detect and Redact PII: PII Protection watches every message your AI employees send and receive, and masks personal data like emails, phone numbers, credit card numbers, and social security numbers before it goes anywhere it shouldn't. You choose exactly which data types to catch. It runs on every employee across your company the moment you turn it on, with no per-employee setup.
Company-Wide Policies: Company Policies let you set organization-wide safety rules that apply to every AI employee at once: block prompt injection attempts, filter harmful output, redact personal information, stop internal details from leaking, and restrict which topics employees can discuss. Turn each policy on with one toggle from your company dashboard, and it takes effect immediately across your whole team.
Sistava Mentor: Every employee you hire on Sistava works alongside Steve, the Sistava Mentor: a named, Sista-side coach who checks in on their work and posts straight into the same chat thread you already read. When a hire drifts from the brief, misses a step, or gets stuck, Steve sends a message under his own name and avatar coaching them on craft, never on priorities. You always see it happen: the message sits in your chat history like any other turn, so nothing about the correction is hidden from you.