The one limit shared by all of them
A streamed response cannot be inspected or blocked as it is being written. The words are already reaching the reader by the time a detector would decide. Put a guardrail on the request leg, or on non-streamed responses, when you need it to actually stop something. On a streaming application, a response-side guardrail observes; it does not protect.Choosing one
Four questions usually settle it.
Do you already run TrustGuard? Then reach for its guardrail. Its findings
line up with Telemetry alerts, so a detection here becomes
part of the same picture as everything else you watch. No provider’s moderation
API can do that.
Do you need the content cleaned rather than the request refused? TrustGuard,
Bedrock and Model Armor can rewrite the content in place and let the call
continue. Azure and OpenAI Moderation return a score, so all they can do is
allow or refuse.
Is the rule something you can write down exactly? An internal hostname, a
ticket reference, a key prefix — that is Regex Replace. It calls nothing, scores
nothing, and does exactly what the pattern says. For anything needing judgement,
you want one of the others.
Do you already own the policy somewhere else? Bedrock and Model Armor reuse
a guardrail or template you built in your own cloud account, so the definition
lives in one place rather than two. That is their real argument, and the cost is
a setup that happens in the provider’s console before this one is any use.
Two things worth knowing before you commit
Only TrustGuard keeps traffic flowing when it cannot be used — unreachable, too slow, refusing the gateway’s credentials, or not configured on the gateway. It forwards the call uninspected and records it as Failed Open, unless you set it to fail closed. Every other provider-backed guardrail here refuses the call in Enforce when its provider is unreachable, so an outage at the provider becomes an outage for your application. Decide which of those you want before you put a guardrail in front of production traffic. Azure never sees the model’s answer. It runs on requests only. If what you need to inspect is what the model said, this is not the one.Combining them
A chain may hold several, and they run in policy-priority order. TrustGuard on the request and a Bedrock guardrail anonymising sensitive data on the response is a common pair: the first refuses what should not go out, the second cleans what comes back. A guardrail that rewrites content changes what any guardrail after it sees.Related
- Policies overview — scope, composition and modes
- TrustGuard — the detectors behind the TrustGuard policy