Skip to navigation

Guardrails

Override prompt injection and DLP policy for one project

A project can override your organization’s prompt injection protection and data loss prevention policy, such as blocking on a customer-facing assistant while a batch job only alerts. Unset fields inherit from the organization. Each resource supports GET, PUT (replaces the whole override), and DELETE (clears it), with the manage_projects scope.

How an override applies

How the request names the projectWhat the override can do
A project API keyTighten or relax the organization policy, exactly as written
The X-Project-Id header or project_id body fieldTighten only. Anything that loosens the organization policy is ignored

GET shows the override as a project API key sees it, so a project named only per request can show a relaxed value while its requests run the organization policy. To run a looser policy, give the project a project API key.

Prompt injection

PUT /v1/projects/{project_id}/pi-settings accepts these fields:

FieldValues
pi_modeDirect injection: off, alert, or block
pi_block_thresholdDirect axis: a segment blocks when its pattern-match score reaches this value, 0 to 1. Must be at least the organization’s pi_pass_threshold
pi_indirect_modeIndirect injection: off, alert, or block
pi_tier2a_block_thresholdScore at which the indirect heuristic signal fires, 0 to 1. Organization default 0.60
pi_tier2b_block_thresholdScore at which the indirect similarity signal fires, 0 to 1. Organization default 0.45
pi_output_actionThe output credential check on non-streaming responses: redact (the default) replaces leaked credentials, observe only records them. route, block, and escalate are accepted but behave like observe
pi_fail_closedtrue rejects requests when detection is unavailable. The default fails open
pi_allowlist_patternsUp to 20 regexes of up to 200 characters. Matching segments skip scanning

pi_pass_threshold, pi_input_action, pi_safer_vendor_route, and pi_log_full_text_on_block are organization-only and return 422 here. Allowlist patterns add to the organization’s list; one broad enough to match ordinary text is ignored.

curl -X PUT https://api-gateway.merge.dev/v1/projects/$PROJECT_ID/pi-settings \
-H "Authorization: Bearer $MERGE_GATEWAY_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"pi_indirect_mode": "block", "pi_tier2a_block_threshold": 0.6}'

The response returns override (what you set), effective (merged), and inherited_fields.

Data loss prevention

PUT /v1/projects/{project_id}/dlp-settings takes an override map keyed by entity type. Each entry sets enabled (scanned or not) and/or action (log, redact, or block), inheriting the other. An entity that isn’t a seeded or custom rule in your organization returns 422 naming it.

curl -X PUT https://api-gateway.merge.dev/v1/projects/$PROJECT_ID/dlp-settings \
-H "Authorization: Bearer $MERGE_GATEWAY_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"override": {"US_SSN": {"action": "block"}, "EMAIL_ADDRESS": {"enabled": false}}}'

The response returns your override plus every catalog entity with org_action, effective_action (null means not scanned), and overridden.

Inheriting again

DELETE, or PUT with {} (PI) or {"override": {}} (DLP), clears a project’s override. To drop one field and keep the rest, send it as null.

Limits

Writes past a limit return 422 naming it. Only active projects count toward per-organization limits.

LimitValue
Projects with a PI override, per organization100
Projects with a DLP override, per organization50
Total size of all PI overrides48 KiB
Total size of all DLP overrides96 KiB. Each project repeats your custom rules, so large custom rules can hit this first

See the Management API reference for full schemas.

Next steps