
Guardian Quickstart
See every prompt, response, and tool call in real time.
Connect a model, tune a profile, and watch your AI traffic in Listen mode — the fastest path to runtime visibility with Cranium Guardian.
01 CONNECT
02 PROFILE
03 TUNE
04 USE CASE
05 LISTEN
-- PROFILE FLOW
-- CANNON
-- ENFORCE
-- SHADOW AI
-- AGENTIC OVERSIGHT
-- REFERENCE
-- SUPPORT

WELCOME
Real-time control across every AI interaction
Cranium Guardian inspects the traffic flowing between your AI tools and the LLMs they call. For each prompt and response it detects the signals defined in a governing profile and records what it would do — block, modify, or pass — according to your policies.
This Quickstart takes you from connecting a model to observing live traffic in Listen mode. You will tune a profile, route on application through Guardian, and read the results in Monitoring and Trace. When you are ready to enforce policy in-line, your dedicated Program Manager helps you make that move — see Beyond the Journey.
What you will have at the end


THE JOURNEY
Five stages, one runtime

BEFORE YOU BEGIN
Have these ready
- Guardian tenant provisioned - Contact your account manager if you need one.
- LLM vendor credentials - Keys for the model vendor you will connect: OpenAI, Claude, or AWS Bedrock.
- An application to route - An AI application whose LLM calls can be pointed at Guardian.
Model Credentials by Vendor
OpenAI Project ID, API Key, and Organization ID

Claude API Key

AWS Bedrock Role ARN
A Model lets Guardian call the LLM and return its response. You will select it when you tune your profile.

STAGE 01 | CONNECT
Connect a Model
Register the LLM Guardian Will Govern
GOAL Create a Model so Guardian can send traffic to your LLM and receive its responses.
INSTRUCTIONS
- Open Inventory > Models and click Create Model.
- Enter a Name, select a Vendor (OpenAI, Claude, or AWS Bedrock), and enter the Vendor Model ID for the specific model version.
- Optionally set the Maximum Tokens for responses using the slider.
- Complete the Secrets section with the vendor's credentials, then click Create.
Detailed Docs


STAGE 02 | PROFILE
Build a Profile
Generate a Starting Guardrail Configuration from Your Deployment
GOAL Create a Profile — a starting guardrail configuration generated from a short description of your AI deployment.
INSTRUCTIONS
- Open Inventory > Profiles and click Create Profile. Enter a Profile Name and choose a Deployment Type — Conversational or Agentic (for agentic, not whether actions are Reversible or Irreversible).
- Answer the Users and System Configuration questions: who the users are (Customers, Employees, or Agents), whether the system prompt is Locked or Configurable, and whether the AI ingests external content or uses persistent memory.
- Select any Sensitive Data Types that may be present — PII, PCI, PHI, Secrets, or Customer Data.
- Choose how output reaches users — Direct or Reviewed — review the summary, and click Create Profile.
Detailed Docs


STAGE 03 | TUNE
Tune the Profile
Set the Model and Signals, and Keep the Profile in Listen
GOAL On the Profile Detail page, select the model, keep the mode on Listen, and decide which signals Guardian detects.
INSTRUCTIONS
- From Inventory > Profiles, select your profile to ope the Profile Detail page. The header shows its status, current mode, and how many signals are enabled.
- Set the Model and Mode: select the Model you connected, and leave the mode on Listen so Guardian analyzes traffic in parallel without changing it.
- Enable the signals the profile should detect. A profile offers sixteen, spanning data (PII/PHI/PCI, Secrets, Named Entities), safety (Toxicity, Illegality), adversarial and agentic (Adversarial, Agentic Instructions), code, and intent and language.
- For each content signal, set what should happen on the prompt and response — Pass, Modify, or Block. In Listen these are recorded as recommendations, not applied.
Detailed Docs


STAGE 04 | USE CASE
Define a Use Case
Bring Your Application Under One Monitoring View
GOAL Create a Use Case governed by your default profile so its traffic is evaluated under a single view.
INSTRUCTIONS
- Open Inventory > Use Cases and open the Create Use Case form. Enter a Name and an optional Description.
- Select a Type — Chatbot or Agent. Type affects reporting only.
- Select your Default Profile. In the Quickstart, this single profile evaluates every interaction in the use case.
- Click Create Use Case.
Detailed Docs


STAGE 05 | LISTEN
Go Live in Listen
Route Traffic Through Guardian and Read What it Would Do
GOAL Send your application's AI traffic through Guardian in Listen mode and review the results.
INSTRUCTIONS
- Rout your application's LLM calls through Guardian, referencing the Use Case you created. Its default profile is already in Listen mode.
- Open Activity > Monitoring and click Show All Traffic, or Open Filters to scope to your Use Case. Each row is one event, with its Safety and Security alerts and the recommended Input and Output action.
- Use Activity > Sessions to see complete interactions reconstructed end to end.
- Open Trace on any event to see what Guardian detected, where in the text, and why — the basis for tuning the profile.
Details Docs


BEYOND THE JOURNEY
Profile Flow
A use case represents one AI application, and its Profile Flow decides which profile evaluates each type of interaction. Events are typed — user to agent, agent to agent, agent to tool, agent to memory, and more — and each can warrant different handling.
GOAL Apply different profiles to different event types so scrutiny matches the real risk of each step.
INSTRUCTIONS
- Open you Use Case and go to Profile Flow. Keep your Default Profile as the fallback for every event type.
- Assign a different profile to a specific event type — for example, stricter code or sensitive-data detection on Agent to Tool than on User to Agent.
- Repeat for any other event types that carry different risk, then save. Every event you do not override keeps using the default.
- Review & Publish. Confirm the recipient, published name, and attached artifacts, then click Publish.
- Locate the card under Published AI Cards, where you can track its status and manage it.
Detailed Docs


BEYOND THE JOURNEY
Test with Cannon
Cannon is the bulk testing tool. You build a collection of prompts, run the whole set through a profile in one go, and get back a count of how many were flagged plus a results table showing which prompts tripped which signals and whether each was blocked, modified, or passed.
GOAL Test a profile against a realistic corpus, including adversarial data, while still in Listen — before it touches live traffic.
INSTRUCTIONS
- Build a Collection of prompts — from Cannon > Collections, or by selecting events in Monitoring's Collections mode and clicking Copy to Collections.
- In Cannon > Runs, start a run by selecting a Collection and a Profile. A run takes at least five minutes and locks the collection and profile while it works.
- Open Cannon > Results to see which prompts tripped which signals, then use Trace to understand why and tun the profile from there.
Detailed Docs


BEYOND THE JOURNEY
Move to Enforce
Listen shows you what your policy would do. Enforce puts it in-line, actually blocking or rewriting content. Because enforcing too early can break agentic runs and depress your success metrics, Enforce is an advanced, guided step.
GOAL Configure in-line enforcement with your dedicated Program Manager once your Listen results are stable.
New profiles start in Listen and require a model before Enforce is available. The wizard only produces a first draft, so you will not yet know which signals fire too often or whether a redaction strips something your app needs. The path is to observe in Listen, use Trace to understand why signals fired, tune, and then enforce.
Because profiles map to individual event types, you can turn Enforce on for just the riskiest turns — the tool call that ingests untrusted content, the step that takes an irreversible action — while the rest keep observing.


BEYOND THE JOURNEY
Shadow AI
SEEING UNMANAGED AI
Surface the AI your organization uses without oversight.
As people adopt AI tools on their own, much of that activity happens without oversight. Shadow AI draws on the activity from your connected SIEM to show which AI services are in use, who is using them, and how much data is moving through them — including usage Guardian does not sit in front of.
GOAL Review organization-wide AI usage discovered from your connected SIEM.
INSTRUCTIONS
- Open Shadow AI > Overview and set the time range — the last 7, 30, or 90 days, or a custom range.
- Read the summary metrics: Total Events, Unique Users, Data Transferred, and Failed Requests.
- Use the Activity Breakdown to view usage by category, subcategory, or service, and the usage-over-time panel to read the trend.
- Drill into the Events, Services, Users, and History pages for detail.
Detailed Docs


BEYOND THE JOURNEY
Agentic Oversight
When a Use Case is set to type Agent, and Agentic Analytics section appears in Use Case Analysis. Agentic workflows raise questions a chatbot does not: how independently the agent acts, how agents coordinate, and what tools they call.
GOAL Understand how autonomous agents behave once their traffic is governed by Guardian.
Open Observe > Use Case Analysis, select an Agent-type use case, and scroll to the Agentic Analytics subsection. The modules there group into three areas:



REFERENCE
Glossary
- Agentic Analytics - Agent-specific charts in Use Case Analysis covering activity,
autonomy, coordination, and tool use for Agent-type use cases. - Cannon - The bulk prompt-testing tool. Runs a Collection through a
Profile and reports how many events were flagged. - Collection - A set of prompts assembled to be tested through a Profile in
Cannon. - Enforce - The Profile mode in which Guardian runs in-line and can block
or modify traffic before it reaches its destination. - Guardian - The engine that evaluates AI traffic, classifying prompts and
responses against a Profile's signals and acting on what it
finds. - Intent - The detected purpose behind a prompt or response, surfaced
in Monitoring and Use Case Analysis. - Listen - The Profile mode in which Guardian runs in parallel, recording a
recommended action without changing traffic. - Model - A configured connection to an LLM (OpenAI, Claude, or AWS
Bedrock) that Guardian can call for a response. - Monitoring - The event-level view of all traffic Guardian has evaluated, one
row per event. - PII / PCI / PHI - Personally identifiable, payment card, and protected health
information Guardian can detect as sensitive data. - Profile - A ruleset defining which signals Guardian detects, how it
responds, and its mode — Listen or Enforce. - Profile Detail - The page where a profile's model, mode, and per-signal prompt
and response actions are configured. - Profile Flow - The per-event-type mapping on a Use Case that assigns a
profile to each interaction — user to agent, agent to tool, and so
on. - Session - A complete interaction reconstructed from the individual events
that make it up. - Shadow AI - Discovery of unmanaged AI usage across the organization,
drawn from a connected SIEM. - Signal - A condition Guardian detects in traffic. A profile exposes
sixteen configurable signals; Observe groups detections into
DLP, Safety, Security, Code, and Content. - Trace - An explanation of a single classification: what Guardian
detected, where in the text, and why. - Use Case - An application or workflow being monitored, mapping Profiles
to its interaction types through the Profile Flow.

WE ARE HERE TO HELP
Govern AI in real time, with a team behind you.
Questions as you connect, tune, and observe? Reach the people and resources that can help you move faster.
- Help Center - support.cranium.ai
- Knowledge Base - docs.cranium.ai
- Training - learn.cranium.ai
- Email - [email protected]





