In Microsoft Foundry, a named set of controls, each pairing a risk with an intervention point and an action, that classifies prompts and completions for harms like hate and fairness, sexual, violence and self-harm, then blocks or annotates them. Formerly content filters; an agent's guardrail entirely replaces its model deployment's.
Also called Content filters.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Foundry guardrail in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Foundry
Formerly called Azure AI Foundry, the Azure platform where AI models and agents are built, evaluated and run within one resource, with evaluations, guardrails and AI red teaming.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Pairing
Deployment pipelines link an item in one stage to its counterpart in the next. Deploying overwrites a linked item, but an unlinked item that just shares its name gets copied across as a duplicate.
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
- Model deployment
Inside a resource, each deployment is a named copy of a Foundry model with its own TPM quota and deployment type. Requests identify the model by this deployment name.
Related terms
- Cognitive Services Contributor
Role for managing resources: it can create them, see and regenerate keys and tailor content filters, though it can't call models with Entra ID; usually more access than a task requires.
- Guardrail intervention point
Where a Foundry guardrail control inspects content: user input, output, tool call or tool response, the last two being preview features for agents only.
- Instant access
A Foundry preview for calling supported models by name, in code or the playground, without first deploying them. A deployment is still needed for data residency, custom content filters or reserved throughput.
- Safety system mitigation layer
Layer of generative AI mitigation provided by the platform, made up of guardrails such as content filters plus abuse monitoring, which classifies harmful prompts and completions and blocks them.