Turn what your tests found into policy you can enforce
Humanbound exports your adversarial test results as a policy file the firewall reads and as rule lists for the gateways, moderation APIs, and filters you already run, so the boundaries your agent was tested against are the boundaries it is held to in production.
A policy file for the firewall
hb guardrails --format yaml writes agent.yaml with your agent’s scope, permitted and restricted intents, and capabilities. The humanbound-firewall judges each request and each piece of ingested content against it.
Rule lists for your other enforcement points
A local run exports the attacks that succeeded as a JSON rule list, and a logged-in project can export an OpenAI Guardrails configuration, ready for gateways, moderation APIs, and your own filters.
A policy that improves with use
On the platform, the exported policy draws on accepted policy recommendations that are derived from every test and monitoring cycle, so it sharpens as more data comes in.
Close the gap between what testing finds and what production enforces
A vulnerability that is documented but not enforced is still open. Guardrails carry what adversarial testing learned into the places where requests and content are actually judged.
hb test runs adversarial conversations against your agent and records which attacks succeeded, with the scope it was tested against. hb guardrails exports that knowledge in the form each enforcement point expects.
Scope defines what your agent may do, what it must not do, and the business context and risk it operates in. In testing, the judge uses it to decide what was a violation. After testing, it becomes the policy your runtime enforces.
One policy file that describes your agent
A firewall that does not know what your agent is for can catch generic attacks, but not a plausible request for something your agent must never do. agent.yaml gives it that definition.
Logged in, the file comes from your project’s policy. Without an account, it comes from your latest local run’s scope or a scope file you pass in. It describes your agent, never an attack.
Loading...
Scope and intents
The business your agent serves, its risk context, and what it is permitted and restricted from doing.
Capabilities
Flags for tools, memory, communication with other agents, and reasoning models. With none declared, the firewall applies its default.
Your deployment settings
Mode, fail behaviour, trust classes, tool handling, timeouts, and decision callbacks, set in code or added to the file.
How the firewall behaves in your environment stays your team’s decision. See how it evaluates what reaches your agent.
Rules for the enforcement points you already run
Traffic to your agent may pass through an API gateway, a moderation service, or your own filter before it reaches the model. Guardrails give each of those layers what your tests learned.
Rule list
After a local run, hb guardrails -o rules.json exports one rule for every attack that succeeded.
OpenAI Guardrails configuration
Logged in, hb guardrails --vendor openai exports a configuration for teams that enforce through OpenAI. The firewall reads neither; it works from agent.yaml.
Threat class
The OWASP category the successful attack addresses.
Pattern
The attack technique that succeeded against your agent.
Severity
How critical the vulnerability was, from the judge’s assessment.
Action
What the enforcement point should do. Every rule defaults to block.
A policy that keeps pace with your agent
A policy written once describes your agent as it was on that day. Agents gain tools and attackers change technique, so a policy nobody revisits drifts from what it protects.
On the platform, the exported policy is built from the latest policy recommendation your team accepted, or from the project’s scope if none has been. Every test and monitoring cycle adds evidence, so the policy sharpens as data comes in.
Export locally, or let the platform keep the policy current
Guardrails export is part of the open-source CLI, and without an account nothing is sent to Humanbound. Log in and the same command exports your project’s policy, built from the recommendations your team accepted.
Open source
Platform
Guardrails export
Enforce what your tests found
Run a test, export your guardrails, and give your firewall and your other enforcement points the same picture of what your agent may and may not do.