Find the insights and best practices about our product.
Guardian Quickstart Guide

Guardian Quickstart

See every prompt, response, and tool call in real time.

Connect a model, tune a profile, and watch your AI traffic in Listen mode — the fastest path to runtime visibility with Cranium Guardian.


01 CONNECT

02 PROFILE

03 TUNE

04 USE CASE

05 LISTEN


-- PROFILE FLOW

-- CANNON

-- ENFORCE

-- SHADOW AI

-- AGENTIC OVERSIGHT

-- REFERENCE

-- SUPPORT





WELCOME

Real-time control across every AI interaction

Cranium Guardian inspects the traffic flowing between your AI tools and the LLMs they call. For each prompt and response it detects the signals defined in a governing profile and records what it would do — block, modify, or pass — according to your policies.

This Quickstart takes you from connecting a model to observing live traffic in Listen mode. You will tune a profile, route on application through Guardian, and read the results in Monitoring and Trace. When you are ready to enforce policy in-line, your dedicated Program Manager helps you make that move — see Beyond the Journey.

What you will have at the end





THE JOURNEY

Five stages, one runtime


BEFORE YOU BEGIN

Have these ready

  • Guardian tenant provisioned - Contact your account manager if you need one.
  • LLM vendor credentials - Keys for the model vendor you will connect: OpenAI, Claude, or AWS Bedrock.
  • An application to route - An AI application whose LLM calls can be pointed at Guardian.


Model Credentials by Vendor

OpenAI Project ID, API Key, and Organization ID

Claude API Key

AWS Bedrock Role ARN


A Model lets Guardian call the LLM and return its response. You will select it when you tune your profile.




STAGE 01 | CONNECT

Connect a Model

Register the LLM Guardian Will Govern


GOAL Create a Model so Guardian can send traffic to your LLM and receive its responses.


INSTRUCTIONS

  1. Open Inventory > Models and click Create Model.
  2. Enter a Name, select a Vendor (OpenAI, Claude, or AWS Bedrock), and enter the Vendor Model ID for the specific model version.
  3. Optionally set the Maximum Tokens for responses using the slider.
  4. Complete the Secrets section with the vendor's credentials, then click Create.


Detailed Docs






STAGE 02 | PROFILE

Build a Profile

Generate a Starting Guardrail Configuration from Your Deployment


GOAL Create a Profile — a starting guardrail configuration generated from a short description of your AI deployment.


INSTRUCTIONS

  1. Open Inventory > Profiles and click Create Profile. Enter a Profile Name and choose a Deployment Type Conversational or Agentic (for agentic, not whether actions are Reversible or Irreversible).
  2. Answer the Users and System Configuration questions: who the users are (Customers, Employees, or Agents), whether the system prompt is Locked or Configurable, and whether the AI ingests external content or uses persistent memory.
  3. Select any Sensitive Data Types that may be present — PII, PCI, PHI, Secrets, or Customer Data.
  4. Choose how output reaches users — Direct or Reviewed — review the summary, and click Create Profile.


Detailed Docs






STAGE 03 | TUNE

Tune the Profile

Set the Model and Signals, and Keep the Profile in Listen


GOAL On the Profile Detail page, select the model, keep the mode on Listen, and decide which signals Guardian detects.

INSTRUCTIONS

  1. From Inventory > Profiles, select your profile to ope the Profile Detail page. The header shows its status, current mode, and how many signals are enabled.
  2. Set the Model and Mode: select the Model you connected, and leave the mode on Listen so Guardian analyzes traffic in parallel without changing it.
  3. Enable the signals the profile should detect. A profile offers sixteen, spanning data (PII/PHI/PCI, Secrets, Named Entities), safety (Toxicity, Illegality), adversarial and agentic (Adversarial, Agentic Instructions), code, and intent and language.
  4. For each content signal, set what should happen on the prompt and responsePass, Modify, or Block. In Listen these are recorded as recommendations, not applied.


Detailed Docs






STAGE 04 | USE CASE

Define a Use Case

Bring Your Application Under One Monitoring View


GOAL Create a Use Case governed by your default profile so its traffic is evaluated under a single view.


INSTRUCTIONS

  1. Open Inventory > Use Cases and open the Create Use Case form. Enter a Name and an optional Description.
  2. Select a Type Chatbot or Agent. Type affects reporting only.
  3. Select your Default Profile. In the Quickstart, this single profile evaluates every interaction in the use case.
  4. Click Create Use Case.


Detailed Docs






STAGE 05 | LISTEN

Go Live in Listen

Route Traffic Through Guardian and Read What it Would Do


GOAL Send your application's AI traffic through Guardian in Listen mode and review the results.


INSTRUCTIONS

  1. Rout your application's LLM calls through Guardian, referencing the Use Case you created. Its default profile is already in Listen mode.
  2. Open Activity > Monitoring and click Show All Traffic, or Open Filters to scope to your Use Case. Each row is one event, with its Safety and Security alerts and the recommended Input and Output action.
  3. Use Activity > Sessions to see complete interactions reconstructed end to end.
  4. Open Trace on any event to see what Guardian detected, where in the text, and why — the basis for tuning the profile.


Details Docs






BEYOND THE JOURNEY

Profile Flow

A use case represents one AI application, and its Profile Flow decides which profile evaluates each type of interaction. Events are typed — user to agent, agent to agent, agent to tool, agent to memory, and more — and each can warrant different handling.


GOAL Apply different profiles to different event types so scrutiny matches the real risk of each step.


INSTRUCTIONS

  1. Open you Use Case and go to Profile Flow. Keep your Default Profile as the fallback for every event type.
  2. Assign a different profile to a specific event type — for example, stricter code or sensitive-data detection on Agent to Tool than on User to Agent.
  3. Repeat for any other event types that carry different risk, then save. Every event you do not override keeps using the default.
  4. Review & Publish. Confirm the recipient, published name, and attached artifacts, then click Publish.
  5. Locate the card under Published AI Cards, where you can track its status and manage it.


Detailed Docs






BEYOND THE JOURNEY

Test with Cannon

Cannon is the bulk testing tool. You build a collection of prompts, run the whole set through a profile in one go, and get back a count of how many were flagged plus a results table showing which prompts tripped which signals and whether each was blocked, modified, or passed.


GOAL Test a profile against a realistic corpus, including adversarial data, while still in Listen — before it touches live traffic.

INSTRUCTIONS

  1. Build a Collection of prompts — from Cannon > Collections, or by selecting events in Monitoring's Collections mode and clicking Copy to Collections.
  2. In Cannon > Runs, start a run by selecting a Collection and a Profile. A run takes at least five minutes and locks the collection and profile while it works.
  3. Open Cannon > Results to see which prompts tripped which signals, then use Trace to understand why and tun the profile from there.


Detailed Docs






BEYOND THE JOURNEY

Move to Enforce

Listen shows you what your policy would do. Enforce puts it in-line, actually blocking or rewriting content. Because enforcing too early can break agentic runs and depress your success metrics, Enforce is an advanced, guided step.


GOAL Configure in-line enforcement with your dedicated Program Manager once your Listen results are stable.


New profiles start in Listen and require a model before Enforce is available. The wizard only produces a first draft, so you will not yet know which signals fire too often or whether a redaction strips something your app needs. The path is to observe in Listen, use Trace to understand why signals fired, tune, and then enforce.

Because profiles map to individual event types, you can turn Enforce on for just the riskiest turns — the tool call that ingests untrusted content, the step that takes an irreversible action — while the rest keep observing.






BEYOND THE JOURNEY

Shadow AI

SEEING UNMANAGED AI

Surface the AI your organization uses without oversight.

As people adopt AI tools on their own, much of that activity happens without oversight. Shadow AI draws on the activity from your connected SIEM to show which AI services are in use, who is using them, and how much data is moving through them — including usage Guardian does not sit in front of.


GOAL Review organization-wide AI usage discovered from your connected SIEM.


INSTRUCTIONS

  1. Open Shadow AI > Overview and set the time range — the last 7, 30, or 90 days, or a custom range.
  2. Read the summary metrics: Total Events, Unique Users, Data Transferred, and Failed Requests.
  3. Use the Activity Breakdown to view usage by category, subcategory, or service, and the usage-over-time panel to read the trend.
  4. Drill into the Events, Services, Users, and History pages for detail.


Detailed Docs






BEYOND THE JOURNEY

Agentic Oversight

When a Use Case is set to type Agent, and Agentic Analytics section appears in Use Case Analysis. Agentic workflows raise questions a chatbot does not: how independently the agent acts, how agents coordinate, and what tools they call.


GOAL Understand how autonomous agents behave once their traffic is governed by Guardian.


Open Observe > Use Case Analysis, select an Agent-type use case, and scroll to the Agentic Analytics subsection. The modules there group into three areas:





REFERENCE

Glossary

  • Agentic Analytics - Agent-specific charts in Use Case Analysis covering activity,
    autonomy, coordination, and tool use for Agent-type use cases.
  • Cannon - The bulk prompt-testing tool. Runs a Collection through a
    Profile and reports how many events were flagged.
  • Collection - A set of prompts assembled to be tested through a Profile in
    Cannon.
  • Enforce - The Profile mode in which Guardian runs in-line and can block
    or modify traffic before it reaches its destination.
  • Guardian - The engine that evaluates AI traffic, classifying prompts and
    responses against a Profile's signals and acting on what it
    finds.
  • Intent - The detected purpose behind a prompt or response, surfaced
    in Monitoring and Use Case Analysis.
  • Listen - The Profile mode in which Guardian runs in parallel, recording a
    recommended action without changing traffic.
  • Model - A configured connection to an LLM (OpenAI, Claude, or AWS
    Bedrock) that Guardian can call for a response.
  • Monitoring - The event-level view of all traffic Guardian has evaluated, one
    row per event.
  • PII / PCI / PHI - Personally identifiable, payment card, and protected health
    information Guardian can detect as sensitive data.
  • Profile - A ruleset defining which signals Guardian detects, how it
    responds, and its mode — Listen or Enforce.
  • Profile Detail - The page where a profile's model, mode, and per-signal prompt
    and response actions are configured.
  • Profile Flow - The per-event-type mapping on a Use Case that assigns a
    profile to each interaction — user to agent, agent to tool, and so
    on.
  • Session - A complete interaction reconstructed from the individual events
    that make it up.
  • Shadow AI - Discovery of unmanaged AI usage across the organization,
    drawn from a connected SIEM.
  • Signal - A condition Guardian detects in traffic. A profile exposes
    sixteen configurable signals; Observe groups detections into
    DLP, Safety, Security, Code, and Content.
  • Trace - An explanation of a single classification: what Guardian
    detected, where in the text, and why.
  • Use Case - An application or workflow being monitored, mapping Profiles
    to its interaction types through the Profile Flow.





WE ARE HERE TO HELP

Govern AI in real time, with a team behind you.

Questions as you connect, tune, and observe? Reach the people and resources that can help you move faster.

Did this answer your question?