> This page is for Gateway.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.merge.dev/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.merge.dev/_mcp/server.

# Guardrails

> Per-project prompt injection and DLP overrides over the API: sparse overrides on top of the organization policy, the tighten-only rule for client-named projects, and write limits.

A project can override your organization's [prompt injection protection](/merge-gateway/security/prompt-injection-protection) and [data loss prevention](/merge-gateway/security/data-loss-prevention) policy, such as blocking on a customer-facing assistant while a batch job only alerts. Unset fields inherit from the organization. Each resource supports `GET`, `PUT` (replaces the whole override), and `DELETE` (clears it), with the `manage_projects` scope.

## How an override applies

| How the request names the project                    | What the override can do                                               |
| ---------------------------------------------------- | ---------------------------------------------------------------------- |
| A project API key                                    | Tighten or relax the organization policy, exactly as written           |
| The `X-Project-Id` header or `project_id` body field | Tighten only. Anything that loosens the organization policy is ignored |

> **Warning**
>
> `GET` shows the override as a project API key sees it, so a project named only per request can show a relaxed value while its requests run the organization policy. To run a looser policy, give the project a project API key.

## Prompt injection

`PUT /v1/projects/{project_id}/pi-settings` accepts these fields:

| Field                       | Values                                                                                                                                                                                                                                                                                          |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pi_mode`                   | Direct injection: `off`, `alert`, or `block`                                                                                                                                                                                                                                                    |
| `pi_block_threshold`        | Direct axis: a segment blocks when its pattern-match score reaches this value, 0 to 1. Must be at least the organization's `pi_pass_threshold`                                                                                                                                                  |
| `pi_indirect_mode`          | Indirect injection: `off`, `alert`, or `block`                                                                                                                                                                                                                                                  |
| `pi_tier2a_block_threshold` | Score at which the indirect heuristic signal fires, 0 to 1. Organization default `0.60`                                                                                                                                                                                                         |
| `pi_tier2b_block_threshold` | Score at which the indirect similarity signal fires, 0 to 1. Organization default `0.45`                                                                                                                                                                                                        |
| `pi_output_action`          | The [output credential check](/merge-gateway/security/prompt-injection-protection#output-credential-check) on non-streaming responses: `redact` (the default) replaces leaked credentials, `observe` only records them. `route`, `block`, and `escalate` are accepted but behave like `observe` |
| `pi_fail_closed`            | `true` rejects requests when detection is unavailable. The default fails open                                                                                                                                                                                                                   |
| `pi_allowlist_patterns`     | Up to 20 regexes of up to 200 characters. Matching segments skip scanning                                                                                                                                                                                                                       |

`pi_pass_threshold`, `pi_input_action`, `pi_safer_vendor_route`, and `pi_log_full_text_on_block` are organization-only and return `422` here. [Allowlist patterns](/merge-gateway/security/prompt-injection-protection#allowlist-patterns) add to the organization's list; one broad enough to match ordinary text is ignored.

```bash
curl -X PUT https://api-gateway.merge.dev/v1/projects/$PROJECT_ID/pi-settings \
  -H "Authorization: Bearer $MERGE_GATEWAY_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"pi_indirect_mode": "block", "pi_tier2a_block_threshold": 0.6}'
```

The response returns `override` (what you set), `effective` (merged), and `inherited_fields`.

## Data loss prevention

`PUT /v1/projects/{project_id}/dlp-settings` takes an `override` map keyed by entity type. Each entry sets `enabled` (scanned or not) and/or `action` (`log`, `redact`, or `block`), inheriting the other. An entity that isn't a seeded or custom rule in your organization returns `422` naming it.

```bash
curl -X PUT https://api-gateway.merge.dev/v1/projects/$PROJECT_ID/dlp-settings \
  -H "Authorization: Bearer $MERGE_GATEWAY_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"override": {"US_SSN": {"action": "block"}, "EMAIL_ADDRESS": {"enabled": false}}}'
```

The response returns your `override` plus every catalog entity with `org_action`, `effective_action` (`null` means not scanned), and `overridden`.

## Inheriting again

`DELETE`, or `PUT` with `{}` (PI) or `{"override": {}}` (DLP), clears a project's override. To drop one field and keep the rest, send it as `null`.

## Limits

Writes past a limit return `422` naming it. Only active projects count toward per-organization limits.

| Limit                                          | Value                                                                                    |
| ---------------------------------------------- | ---------------------------------------------------------------------------------------- |
| Projects with a PI override, per organization  | 100                                                                                      |
| Projects with a DLP override, per organization | 50                                                                                       |
| Total size of all PI overrides                 | 48 KiB                                                                                   |
| Total size of all DLP overrides                | 96 KiB. Each project repeats your custom rules, so large custom rules can hit this first |

See the [Management API reference](/merge-gateway/management-api) for full schemas.

## Next steps

#### [Prompt injection protection](/merge-gateway/security/prompt-injection-protection)

The organization policy projects inherit

#### [Data loss prevention](/merge-gateway/security/data-loss-prevention)

Manage the entity catalog and default actions

#### [Projects API](/merge-gateway/automation/projects-api)

Manage the rest of a project's configuration