Policy: AWS > Bedrock > Guardrail > Settings
Check or enforce the configuration of an AWS Bedrock guardrail's content (messaging, content filters, denied topics, word filters, sensitive information policies, contextual grounding) against the sub-policies declared under AWS > Bedrock > Guardrail > Settings > *.
Content-filter sub-policies (Hate, Insults, Sexual, Violence, Misconduct, Prompt Attack) default to the AWS console "Default settings" baseline (MEDIUM strength on input and output for the five harmful-content categories, HIGH input on Prompt Attack), so flipping to Enforce: Configured without setting individual sub-policies produces a working baseline guardrail. Override individual sub-policies to tighten (HIGH) or disable (NONE) per category. Recommended workflow: Check: Configured first to surface any diff against the guardrail's current config, then Enforce: Configured once the diff matches intent.
The remaining sub-policies (denied topics, custom words, AWS managed word lists, PII entities, regex patterns, contextual grounding thresholds, blocked messaging, description, KMS key) default to "not configured" because they're inherently customer-specific or only meaningful in narrow scenarios (e.g., grounding thresholds matter only when the guardrail is used with retrieved context); those sub-policies are excluded from the diff until set.
Targets
This policy targets the following resource types:
Related Policies
- Automated Reasoning Policy
- Blocked Input Messaging
- Blocked Outputs Messaging
- Content Policy
- Contextual Grounding Policy
- Cross-Region Guardrail Profile
- Description
- KMS Key
- Sensitive Information Policy
- Topic Policy
- Word Policy
Controls
Setting this policy configures this control:
Policy Packs
This policy setting is used by the following policy packs:
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/security
- tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings
- turbot graphql policy-type --id "tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettings"
Get Policy TypeGet Policy Settings