The safeguard library

See the safeguards before you use them.

A Control Pack is a reusable set of safeguard rules. Each pack explains when it applies, what you need to decide, what to build, and which evidence to keep. Some include starter patterns and test scenarios.

Want to see how a pack behaves? Browse the published examples to inspect and run one published example for every Control Pack.

34 versioned packs · Browse below while search loads.

Browse

Control Packs

AI systems

4 packs
AI-004v1.0.0
review

Grounded Model Output and Instruction Separation

Decide what a model's output is allowed to be used for before it is used, keep retrieved or user-supplied content separated from the instructions that carry authority, and make a low-confidence or unavailable answer a defined outcome rather than a silent one.

AI
Open pack page →

Automation

5 packs
AUT-005v1.0.0
review

Work That Should Have Happened

Say when automated work is expected, and raise a signal when it does not happen -- because a job that stops running produces no error to notice.

AutomationReliabilityObservability
Open pack page →

Input and files

2 packs
INP-001v1.0.0
review

Untrusted Input Handling

Validate, bound, and safely render content that people outside the system control, and keep it from reaching an interpreter, a privileged path, or another user unchecked.

DataAutomation
Open pack page →
INP-002v1.0.0
review

Uploaded File and Document Handling

Decide which file types and sizes you accept, store them under a name and location the uploader does not control, and never serve or open one in a way that lets its content or name reach somewhere it should not.

DataAutomation
Open pack page →

Identity and access

5 packs
IDN-004v1.0.0
review

Access Rights and Authorization Boundary

State who may perform which operations, enforce it where the action happens rather than only in the interface, remove access deliberately rather than by habit, and record every change to who holds what.

IdentityObservability
Open pack page →

Data

7 packs
DAT-003v1.0.0
review

Tenant Data Isolation

Define storage, query, cache, and operational boundaries that prevent one tenant's data from appearing in another tenant's context.

DataPrivacyMulti tenancy
Open pack page →
DAT-007v1.0.0
review

Stored Data and Key Boundary

Name every store and copy that holds the data, state what protects each one at rest, and confirm who holds the key, what it opens, and how it is replaced.

DataPrivacyRecovery
Open pack page →

Reliability

4 packs

Production change

3 packs

Observability

4 packs
OBS-003v1.0.0
review

Failure Visibility and Escalation

Decide which failures a person must be told about, who is told, and how fast — so a broken job, a backed-up queue, or a degraded dependency is not discovered by a customer first.

ObservabilityReliability
Open pack page →
How these safeguards work
The review, API, agent tools, and download use the same versioned pack rules. All current packs are still in review. They provide design guidance; they do not certify your project or prove its safeguards work.

Related discoveries

Recent records for this pack

View all in Trends