Policy: AWS > Bedrock > Guardrail > Settings > Sensitive Information Policy > Regexes Config
List of custom regex patterns the guardrail should detect, anonymize, or block. An empty list (the default) means "not configured" and is excluded from the diff and the enforced sensitiveInformationPolicyConfig.
The optional inputAction / outputAction / inputEnabled / outputEnabled fields per-pattern override the guardrail-wide action for that direction.
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|---|
Default | |
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/security
- tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettingsSensitiveInformationPolicyRegexesConfig
- turbot graphql policy-type --id "tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettingsSensitiveInformationPolicyRegexesConfig"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/aws-bedrock#/policy/types/bedrockGuardrailSettingsSensitiveInformationPolicyRegexesConfig"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI