# uip agent guardrails

> List guardrail definitions, BYOG guardrails, LLM-as-judge models, and the guardrail catalog with `uip agent guardrails`.

`uip agent guardrails` is a read-only discovery group for the guardrails an agent project can reference — built-in validators and bring-your-own-guardrail (BYOG) connections — plus the models available for the LLM-as-judge guardrail and the authored catalog metadata (descriptions, use cases, examples) for each validator. It does not attach a guardrail to a project; that's done by hand-editing `agent.json`.

## Synopsis

```
uip agent guardrails list [--byo]
uip agent guardrails llm-as-judge-models
uip agent guardrails catalog [--validator <id>]
```

All invocations honor the [global options](./global-options.md) (`--output`, `--output-filter`, `--log-level`, `--log-file`). Exit codes follow the [standard contract](./exit-codes.md).

## uip agent guardrails list

List available guardrail definitions, including disabled ones (a disabled BYOG configuration is worth showing — otherwise it's indistinguishable from one that was never set up).

### Options

| Flag | Purpose |
|---|---|
| `--byo` | Filter to bring-your-own (BYOG) guardrails only. |

### Examples

```bash
uip agent guardrails list

uip agent guardrails list --byo
```

### Data shape (--output json)

```json
{
  "Code": "GuardrailDefinitionsList",
  "Data": [
    {
      "Validator": "pii_detection",
      "IsByo": false,
      "Status": "Available",
      "AllowedScopes": ["Agent", "Llm", "Tool"],
      "GuardrailStages": { "Agent": ["PreExecution", "PostExecution"], "Llm": ["PreExecution", "PostExecution"], "Tool": ["PreExecution", "PostExecution"] },
      "Parameters": [
        { "Type": "enum-list", "Id": "entities", "Required": true, "DefaultValue": ["Email", "Address"], "Options": ["Person", "Address", "Email", "..."] }
      ]
    }
  ]
}
```

`Validator` is not unique — a BYOG definition can share a built-in's name (a tenant can have two `harmful_content` entries). Use `IsByo` plus the `Byo*` fields (`ByoValidatorName`, `ByoConnectionId`, `ByoConfigurationId`, `ByoConnectorName`, `ByoConnectorKey`, `FolderKey`) to tell them apart — `ByoValidatorName` and `ByoConnectionId` are the two values a coded agent passes to `ByoValidator(...)`.

## uip agent guardrails llm-as-judge-models

List LLM models available for the LLM-as-judge guardrail. Requires login.

### Example

```bash
uip agent guardrails llm-as-judge-models
```

### Data shape (--output json)

```json
{
  "Code": "LlmGatewayModelsList",
  "Data": [
    { "ModelId": "anthropic.claude-haiku-4-5-20251001-v1:0", "DisplayName": "Claude Haiku 4.5", "Vendor": "AwsBedrock", "ModelFamily": "AnthropicClaude", "SubscriptionType": "UiPathOwned", "IsByo": false, "IsPreview": false, "IsBlockedByPolicy": false }
  ]
}
```

Models blocked by tenant policy are filtered out before the list is returned.

## uip agent guardrails catalog

Fetch authored catalog metadata (descriptions, use cases, examples) for guardrail validators.

### Options

| Flag | Purpose |
|---|---|
| `--validator <id>` | Filter to a single validator by its snake_case ID (e.g. `pii_detection`). |

### Examples

```bash
uip agent guardrails catalog

uip agent guardrails catalog --validator pii_detection
```

### Data shape (--output json)

```json
{
  "Code": "GuardrailCatalog",
  "Data": {
    "schema_version": "1.0.0",
    "guardrails": [
      { "validator_id": "pii_detection", "display_name": "PII Detection", "type": "BuiltIn", "status": "Available", "description": "...", "use_cases": ["..."], "examples": [] }
    ]
  }
}
```

If the catalog feature isn't yet enabled for the tenant, this fails with `Code: "GuardrailCatalogUnavailable"`.

## Related

- [`uip agent review`](./uip-agent-review.md) — one of its rule categories is `guardrails`.

## See also

- [Authentication](./authentication.md) — required for `llm-as-judge-models`.
- [Global options](./global-options.md), [Exit codes](./exit-codes.md).
