Overview
Portkey enables organization owners to enforce request guardrails at the organization level. This feature ensures that all API requests made within the organization comply with predefined policies, enhancing security, compliance, and governance.How It Works
Organization owners can define input and output guardrails in the Organization Guardrails section. These guardrails are enforced on all API requests made within the organization, ensuring uniform policy enforcement across all users and applications.- Input Guardrails: Define checks and constraints for incoming LLM requests.
- Output Guardrails: Ensure LLM responses align with organizational policies.
Guardrials Docs
Learn about the different Guardrails you can set up in Portkey
Configuration
Setting Up Guardrails Requirements
- Head to
Admin Settingson the Portkey dashboard - Navigate to the
Organisation Guardrailssection - Add your
Inputand/orOutputGuardrails - Save your changes
Excluding Workspaces
Some workspaces — an internal evaluation sandbox, for example — may need to run without the organisation’s default guardrails. You can exempt them individually while every other workspace stays covered. Exclusions are managed per guardrail direction through the Admin API, and require an organisation service API key with theorganisation_exclusions.update and organisation_exclusions.list scopes.
Workspace exclusions are currently available via the API only. Support for managing them from the Portkey dashboard is coming shortly.
/workspace-exclusions/output-guardrails for output guardrails, and set excluded to false to bring a workspace back under enforcement. Pass override_existing: true to replace the current exclusion list rather than merge into it. The matching GET endpoint returns the workspaces currently excluded.
Best Practices
- Clearly communicate guardrail requirements to all developers in your organization.
- Maintain internal documentation on your guardrail policies to ensure consistency.

