Skip to main content
Glama

create_guardrail

Create an LLM or MCP-tool guardrail with checks and actions, then map it to servers to enforce policy on model requests and tool calls.

Instructions

Create an LLM or MCP-tool guardrail. LLM guardrails require checks and actions; MCP-tool guardrails can be created first and mapped to servers afterward. The new version becomes the policy anchor for downstream use.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesName of the guardrail
checksNoChecks to apply; at least one entry. Required when target is llm.
targetNoLLM traffic by default, or MCP tool calls
actionsNoActions to take when guardrail checks pass or fail
workspace_idNoWorkspace ID to create the guardrail in
organisation_idNoOrganisation ID (required if workspace_id not provided)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYesWhether the tool call succeeded and returned structured data
dataNoStructured success payload when ok is true
errorNoStructured error payload when ok is false

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv0.12.2
    • changedInput schema / properties / checks / description
      Previous value: -"Array of checks to apply (at least one required)"New value: +"Checks to apply; at least one entry. Required when target is llm."
    • addedInput schema / properties / target
      Added value: +{
      +  "description": "LLM traffic by default, or MCP tool calls",
      +  "enum": [
      +    "llm",
      +    "mcp_tools"
      +  ],
      +  "type": "string"
      +}
    • changedInput schema / required
      Previous value: -[
      -  "name",
      -  "checks",
      -  "actions"
      -]New value: +[
      +  "name"
      +]
  2. Changed1 schema field changedv0.11.5
    • changedInput schema / properties / checks / items / properties / parameters / description
      Previous value: -"Check-specific configuration parameters"New value: +"Check-specific configuration. Supported examples include requestParametersCheck and parameters.forwardHeaders; forwarded headers can expose sensitive values, so allow only the minimum required names."
  3. Addedv1.0.1
  4. Removed
  5. First observed

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare it as non-read-only, non-idempotent, open-world, and not destructive, so safety profile is largely covered. The description adds one useful behavioral fact — that the new version becomes the policy anchor for downstream use — but says nothing about permissions, scope anchoring side effects, or what happens to prior versions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each carrying a distinct point (what it creates, per-target requirements, downstream anchoring). Front-loaded and efficient; no wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given an output schema exists, return values need not be described. The description covers the two target modes, ordering semantics, and the versioning consequence, which is enough to call the tool correctly. Minor gap: no mention of required workspace/org scoping behavior.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all six parameters including nested checks and actions. The description adds conditional logic (checks/actions required for llm; MCP-tool can defer mapping), which slightly enriches parameter meaning but largely restates schema constraints.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (create a guardrail) and distinguishes two flavors (LLM vs MCP-tool). It does not name sibling tools like update_guardrail or create_mcp_server, but the LLM/MCP distinction is itself differentiation within the resource.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives a soft ordering hint: MCP-tool guardrails can be created first and mapped to servers afterward, while LLM guardrails require checks and actions. That implies when each target applies but does not explicitly say when to use create_guardrail vs update_guardrail or how it relates to the other guardrail-mapping tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools