Guardrails
Guardrails are the limits your team works within. They keep an AI team safe and within budget. You set them for the whole Force on the Guardrails tab, for each member on the Authority tab, and for individual playbook steps.
Three layers of limits
| Layer | Where you set it | Applies to |
|---|---|---|
| Force-wide | Guardrails tab | Every member of the Force |
| Per member | Member form, Authority tab | One member, on every step |
| Per playbook step | Work tab, Deliver and Parallel steps | The action steps of the playbook |
The strictest limit always wins. Trust level, approval mode and editing a member cannot lift a limit.
Enforced limits
An enforced limit is a hard guarantee checked by the platform. The action is removed from what the AI is offered, so it cannot be done, whatever the instructions say.
| Limit | What it blocks |
|---|---|
| Never writes anywhere | Any change to a system. It also covers the other two |
| Never sends email or messages | Sending anything |
| Never deletes anything | Deleting anything. Deletes never reach the Approvals queue |
For one member, tick the boxes under What they must never do on the member's Authority tab. The roster then shows an "Always:" line. For a playbook step, tick Permanent limits in the step's settings. See Playbooks.
Force-wide instructions
Instructions are plain-language guidance added to every member's prompt. They add to the platform's own prompt and take precedence over a member's own instructions if they conflict. The tag reads Prose only.
Open the Guardrails tab
Open a Force and choose Guardrails. Non-admins see the fields but cannot change them.
Add an instruction
Click + Add instruction. You can add up to 8, each up to 1000 characters, with a live counter. For example: "Start every response with the current work status."
Read any warning
Text that sounds safety-related (send, email, write, update, delete) shows This sounds safety-relevant with a button to turn it into an enforced limit and remove the text. If the limit is already on, the button says "Remove this prose; the enforced limit already guarantees it". Text about memory shows This may restate platform memory behavior.
Screenshot placeholderScreenshot to add: An instruction with the safety-relevant warning and its button. Save
Click Save guardrails. A toast says "Force-wide guardrails saved".
Run budget per step
A budget stops one member step from using too much. When a step reaches it, the step pauses and asks you to continue. It never stops for good and it cannot be turned off. The tag reads Pauses only.
| Field | Type | Required | Default | What it does |
|---|---|---|---|---|
| Spend budget | Number (USD) | No | Platform default (about $1) | Smallest increment 0.01. |
| Token budget | Number (tokens) | No | Platform default (about 1 million) | Increment 1,000. |
| Time budget | Number (minutes) | No | Platform default (about 15) | Stored as seconds. |
- Leave a field empty to use the platform default. Each field shows Default and Max beneath it.
- A value must be above zero: "Enter a number greater than zero, or leave empty for the platform default." Above the maximum: "Above the maximum of (value)."
- The maximum is set by your administrator in the platform's configuration, not on a settings page.
- Time pauses before the step would time out, so you get a chance to continue.
- A member's own Runs for up to setting (5 minutes to 1 hour) is separate. See Step 7.
When a step pauses
The team stops at that step and the job becomes Needs you, with a question like "(member) paused: (detail) Continue?". You are notified once. Click Continue on the Ask page or in Needs you to resume at the same step.
Other safety checks always apply, whatever your budget: repeated identical actions, repeated errors, stalls and text loops also pause the step.
Preview what a member sees
Click Preview what a member sees, and pick a member under Preview for member. Actual prompt order shows: 1) Force-wide instructions, then 2) the member's own instructions. Enforced limits are checked by the platform and cannot be overridden by either.
Who can change guardrails
Admins on the Force. Everyone else sees them read-only.
Back to Agent Force. See also Step 5 of the wizard.