Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
AWS
Loading policies...

Policy: AWS > Bedrock > Guardrail > Settings

Check or enforce the configuration of an AWS Bedrock guardrail's content (messaging, content filters, denied topics, word filters, sensitive information policies, contextual grounding) against the sub-policies declared under AWS > Bedrock > Guardrail > Settings > *.

Content-filter sub-policies (Hate, Insults, Sexual, Violence, Misconduct, Prompt Attack) default to the AWS console "Default settings" baseline (MEDIUM strength on input and output for the five harmful-content categories, HIGH input on Prompt Attack), so flipping to Enforce: Configured without setting individual sub-policies produces a working baseline guardrail. Override individual sub-policies to tighten (HIGH) or disable (NONE) per category. Recommended workflow: Check: Configured first to surface any diff against the guardrail's current config, then Enforce: Configured once the diff matches intent.

The remaining sub-policies (denied topics, custom words, AWS managed word lists, PII entities, regex patterns, contextual grounding thresholds, blocked messaging, description, KMS key) default to "not configured" because they're inherently customer-specific or only meaningful in narrow scenarios (e.g., grounding thresholds matter only when the guardrail is used with retrieved context); those sub-policies are excluded from the diff until set.

Targets

This policy targets the following resource types:

  • AWS > Bedrock > Guardrail

Related Policies

  • Automated Reasoning Policy
  • Blocked Input Messaging
  • Blocked Outputs Messaging
  • Content Policy
  • Contextual Grounding Policy
  • Cross-Region Guardrail Profile
  • Description
  • KMS Key
  • Sensitive Information Policy
  • Topic Policy
  • Word Policy

Controls

Setting this policy configures this control:

  • AWS > Bedrock > Guardrail > Settings

Policy Packs

This policy setting is used by the following policy packs:

  • Enforce Content Filtering for AWS Bedrock Guardrails

Policy Specification

Schema Type
string
Default
Skip
Valid Values [YAML]
  • Skip
    
  • Check: Configured
    
  • Enforce: Configured
    
Examples [YAML]
  • Check: Configured
    

Category

  • Security

In Your Workspace

  • Policy Settings by Type report

Developers

    Category URI
    • tmod:@turbot/turbot#/control/categories/security
  • Policy Type URI
    • tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings
  • GraphQL
    • query policyType(id: "tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings") { … }
    • query policySettings(filter: "policyTypeId:'tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings'") { … }
    • query policyValues(filter: "policyTypeId:'tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings'") { … }
  • CLI
    • Get Policy Type
    • turbot graphql policy-type --id "tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings"
    • Get Policy Settings
    • turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings"
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
182
Mods
520
Resource Types
9,028
Policies
3,512
Controls
1,933
Quick Actions
547
IAM