The catalog is fixed: eight detectors, listed under Detectors → Catalog. Pick one, name it, configure it, then reference that instance from a policy.
Data loss prevention
PII and secrets. The only detector that can mask in flight.
Content security
Jailbreaks, toxicity, moderation, documents, and URLs.
Agent and MCP
Indirect prompt injection in tool-sourced content.
The catalog
Sides is which directions a detector supports. Masks marks the one detector that can rewrite the payload, which is what makes the Transform action available.Data loss prevention
Content security
Agent & MCP security
How much there is to configure
Most of these have a single setting. Knowing which is which saves you opening each one:
Protection Sensitivity
is three preset cards — Permissive, Balanced (recommended), Strict —
not a number you type.
How the catalog, detectors, and policies fit together
- A catalog detector is a fixed capability. You cannot change what it looks for, only how it is tuned.
- A detector is a named, reusable instance you create from a catalog entry. It is detection-only — it never decides what happens.
- A policy references detectors in rules that set the action — Monitor, Block, Transform — and the phase, Input or Output.
- Data Loss Prevention is the only detector where Transform is valid. Selecting Transform for any other detector is rejected when you save the policy.