SubLaneSubLane

Content rules

Check outgoing JSON text with workspace terms and regular expressions.

Workspace administrators configure Administration → Content rules. Rules are optional and disabled by default. They apply to every account pool and member in that workspace; the gateway key determines the workspace.

Content rules in a synthetic verification workspace

Choose a mode

ModeBehavior
OffForward without content checks.
ObserveForward unchanged requests and record matched rule IDs in request diagnostics. Matching content still goes upstream.
BlockReject matching requests before account selection or upstream dispatch. Incomplete checks also stop forwarding.

Start with Observe if you need to assess false positives. Switch to Block when the configured rules are ready. Observe does not prevent disclosure.

Configure and test a rule

Choose Configure rules, then add a name, match type, matching content and enablement. Text rules use case-sensitive substring matching. Regular expressions use Go RE2 syntax; lookaround and backreferences are unsupported. Use (?i) for case-insensitive expressions. Invalid expressions and expressions matching an empty string cannot be saved.

Use specific values rather than broad variable names such as api_key, which may occur in ordinary code. Keep secrets out of the rule name. Matching content is encrypted with a workspace-bound instance key and is never returned in metadata. When editing a saved rule, leaving matching content blank retains the encrypted value. Removing the rule removes it from subsequent checks.

Expand Test this rule and enter a temporary sample. Testing checks only that rule, calls no model and does not save the sample. The input clears after the test. Synthetic examples such as DEMO_TOKEN_[A-Z0-9]{8} are suitable for checking expression syntax; do not put real secrets into public issues or screenshots.

Regular-expression input highlights character classes, groups, anchors, quantifiers and escapes as you type. Only your current draft is visible; saved expressions remain hidden. Literal terms keep masked inputs. Highlighting does not validate or execute the expression; the server still checks Go RE2 syntax.

Save applies the complete policy, and the change is transactionally audited. A stale edit cannot overwrite a newer version; reload before editing again. Changes apply to subsequent checks, including existing WebSocket conversations. A request that already passed its check is not retroactively canceled.

Coverage and limits

Checks scan decoded JSON strings, including instructions, message history, tool definitions, arguments and outputs, JSON property names and duplicate fields. Responses, Chat Completions, compaction, Claude Messages and Gemini generation use the same check. WebSocket turns check reconstructed context; local prewarm is checked before retaining text.

There are at most 50 rules, 64 UTF-8 bytes per rule name and 1,024 bytes per pattern. Scanning covers at most 8 MiB of JSON and 64 nesting levels, also respecting the gateway's request-size limit. In Observe mode an incomplete scan is marked and forwarding continues. In Block mode it returns content_check_unavailable and does not forward. A match returns HTTP 403 with content_policy_blocked, or the corresponding native-protocol or WebSocket error.

This is text pattern matching, not a complete data-loss prevention system. Images, binary attachments, base64 and other deliberate encodings are not decoded. Values split across fields may not match. Requests sent directly to providers or other endpoints bypass this gateway. There is no automatic replacement or client bypass option.

Diagnostics and backups

Request details retain the handling mode, policy version, matched rule IDs and incomplete-check state, using existing request-history retention and ownership rules. They contain no matched snippets, patterns or request bodies. Administrators see their workspace records; members see only their own. Blocked requests make no generation call, consume no generation allowance and do not put an account into cooldown.

If the client-supplied model label matches a rule, it is also omitted from logs, request history and usage summaries. An incomplete check omits that label as well. Execution and allowance settlement keep their original model internally.

Backups include encrypted rules and the instance key. Startup and archive verification check decryption and rule validity; a missing or mismatched key cannot silently reset the policy. Preserve the original key with the database. Per-hit external notifications are not implemented.