Skip to main content
This guide takes you from zero AI-specific security controls to a live guard inspecting your traffic. By the end, you will have a request flowing through the BeyondGuard Guard Gateway, a verdict on that request, and threat events appearing in your control plane. Because the gateway speaks the OpenAI chat completions format, the only things that change in your application are the base URL and one header.
1

Get your credentials

BeyondGuard is provisioned for enterprise teams through a guided onboarding.
  1. Visit beyondguard.ai and request access.
  2. The BeyondGuard team provisions your organization and gives you access to your control plane panel.
  3. In the panel, create a gateway and issue an API token. You will need three values: your Guard URL, your gateway ID, and your X-Guard-Token.
Keep the token secure — store it in your secrets manager, not in source code.
2

Point your client at the Guard Gateway

Send your request to the gateway instead of directly to your model provider. The gateway inspects the prompt, applies your active guards and policies, forwards cleared traffic to the configured model, and returns the response with a security verdict attached. No SDK is required — any OpenAI-compatible client or a plain HTTP call works.
See the Guard Gateway API reference for the full request and response shape.
3

Read the verdict

Every response combines the standard chat completions envelope with BeyondGuard metadata. Check whether the request passed, and read the reply:
When is_passed is false, inspect __beyond_guard_rejection_codes and __beyond_guard_checks_result.details to see exactly which control fired and why. Each decision carries a confidence score and a reason code, and the full event streams to your SIEM.
4

Tune policies and switch to enforcement

In the control plane, review the threat events your gateway has captured — filter by guard, threat category, or time window to understand your threat surface before you tighten anything.Start each guard in observation mode (scoring only, nothing blocked) to build a baseline, then move your highest-risk controls to enforcement, where each interaction resolves to allow, deny, mask, or rewrite. Set thresholds and outcomes per control in Policy Configuration.
Start with Prompt Guard — it covers the widest range of input-layer threats and gives you the fastest signal about your application’s exposure. Once you have a baseline, add Context Guard to close the output boundary, then layer in RAG, File, Agent, and MCP Guards as your retrieval, agent, and tool integrations grow.
You do not need to reach L5 (Continuous Governance) on day one. BeyondGuard’s maturity model is designed to let you start at L1 (Visibility) — simply collecting threat data — and advance as your team builds confidence and your policies mature.