Skip to main content
Deploying BeyondGuard follows a deliberate, layered sequence: start with Prompt Guard in observation mode to establish a threat baseline, then expand coverage guard by guard until you reach full enforcement across every layer of your AI stack. This approach ensures you have real data to tune policies before activating blocking behavior — minimizing disruption while maximizing protection. Most teams reach observable coverage in week one, full enforcement in weeks four to six, and governance readiness within three months.

Before you begin

Make sure you have the following in place before starting:
  • A BeyondGuard account with access to the Control Plane
  • Your Guard URL, gateway ID, and X-Guard-Token — issued from your panel
  • An AI application or pipeline you want to protect — a chatbot, an agentic workflow, a RAG pipeline, or any LLM-backed service
1

Connect through the Guard Gateway

Route your application’s AI traffic through the Guard Gateway instead of calling your model provider directly. Because the gateway speaks the OpenAI chat completions format, the only change to your application is the base URL and the X-Guard-Token header — no changes to your prompts or model configuration. The Quickstart walks through the first request end to end.
2

Enable Prompt Guard in observation mode

In the Control Plane, create a project for your application and enable Prompt Guard in observation mode. In this mode the guard scores every interaction and logs what it would have done, without blocking anything. Start here: Prompt Guard has the broadest coverage of any single guard and gives you the fastest signal about your exposure.
3

Review threat events and tune policies

Let traffic flow for a few days, then open the Threat Events dashboard. Filter by guard, threat category, and time window to understand your real threat surface. Use that data to tune policies: set sensitivity thresholds, add allowlists for known-safe patterns, and add blocklists for known-bad ones. The goal is accurate, low-noise detection before you enforce anything.
4

Move your highest-risk controls to enforcement

Once your policies reflect your environment, switch your highest-risk controls from observation to enforcement. In enforcement, each interaction resolves to allow, deny, mask, or rewrite with a confidence score and reason code. Flip critical controls first and watch your false-positive rate as you go — tune thresholds rather than accepting noise.
5

Expand guard by guard

With Prompt Guard enforcing, add the next layer that carries risk for your deployment. A common order is Context Guard (to close the output boundary), then RAG Guard and File Guard as your retrieval and upload paths mature, then Agent Guard and MCP Guard as your agent and tool integrations grow. Bring each guard through the same observe → tune → enforce cycle.
6

Reach full enforcement and governance

With all six guards live and enforcing, you have reached an L3 (Enforcement) posture — your organization is measurably protected across the value chain. From there, feed Red Teaming findings back into your policies to close gaps, and use the Control Plane’s compliance reporting to advance toward L4 (Governance) and L5 (Continuous Assurance).
Deploy one guard at a time and let each reach a stable, tuned baseline before enabling the next. Rushing to full coverage before tuning is complete can generate elevated false-positive rates, eroding trust in the platform and creating alert fatigue for your security team.
This layered path maps directly to BeyondGuard’s maturity model: observation mode is L1 (Visibility), tuned policies are L2 (Policy), selective and then full enforcement are L3, and Red-Team-driven policy updates carry you to L4 and L5.