Check your agent's protections before publishing
Test content guardrails, restrict installation to the correct domains and choose how to handle verified users and personal data.
Open copy menu
Protections address different questions: what the agent handles, where the widget works and whose data an action may use. Check these separately before customer use.
Choose protection for the task
Section titled “Choose protection for the task”| What you need to check | Start here | Verification |
|---|---|---|
| The agent handles harmful messages or instruction-bypass attempts appropriately. | Settings → AI → Content Safety | Test guardrails and an ordinary customer question. |
| The widget works only on your websites. | Settings → Security | Test on an allowed domain and another domain. |
| An action uses the correct signed-in customer’s details. | Identity verification and the action’s permissions | Test with a verified and an unverified customer. |
| Contact details are collected as agreed. | Lead collection fields, consent and privacy link | Check the visible form and saved details. |
Configure and test content guardrails
Section titled “Configure and test content guardrails”Enable guardrails
Open the agent’s Settings → AI → Content Safety. Check Enable guardrails and choose Show the standard safety message or Show your own message for a blocked message.
Write your message if needed
Write a Custom message that explains the agent’s task and the customer’s next available step. Save settings and wait for confirmation.
Try the protection
Open Test guardrails, enter a Message to test and choose Test. Try an ordinary customer question and a message asking the agent to bypass its instructions. The test does not change settings or consume message credits.
Verify the conversation too
Test the agent in a normal preview conversation with the saved settings. Check that allowed questions still get useful answers and blocked cases give customers a clear next step.
Restrict installation domains
Section titled “Restrict installation domains”Open Settings → Security, enable domain restriction and enter Allowed domains, one name per line. Add example.com and www.example.com separately if you use both. These are example addresses; replace them with your own domains. Save and test on the website rather than only in the dashboard preview.
Domain restriction does not identify a signed-in user. For an action such as looking up a customer’s own order, configure identity verification and ensure the receiving API checks access to the requested data. An order number typed into the conversation is not authorization.
Captured data and access removal
Section titled “Captured data and access removal”Collect only the details needed for the task. Check lead collection consent and privacy settings and your organization’s approved handling before publishing the form.
Pausing an agent, removing installation code and removing workspace membership are different from deleting personal data already saved. The account and workspace guide provides maintained privacy sources and the data-request process.
If the test fails
Section titled “If the test fails”| Observation | What to check next |
|---|---|
| The guardrail test fails or reports too many requests. | Read the error, wait if needed and retry. Failure does not establish that a message is allowed. |
| The widget does not open on your website. | Check the actual domain, saved restriction and installation troubleshooting . |
| An action cannot get the customer’s data. | Check identity verification and the receiving API’s permissions. |
| An ordinary question gets no useful answer. | Check sources, instructions and the protection message, then retest the change. |
Credit balance, sending rate and personal-data warnings
Section titled “Credit balance, sending rate and personal-data warnings”Message-credit balance describes how much service the workspace can use. Sending-rate limits protect a different boundary: messages sent too quickly. If the widget asks the visitor to wait, wait before retrying. Do not disable protection or issue parallel retries to work around the error.
A personal-data warning in the message field advises the visitor; it does not automatically block sending. Check your data-collection policy and visible privacy information. A guardrail-test detection, a message-field warning and your organization’s data-request process are separate things.