AI guardrails and approvals
Docs · AI control
Decide what the AI may talk about and which of its actions wait for the visitor or a teammate to confirm. Guardrails and approvals are on every plan where the AI is on.
Before you start
- Difficulty: Easy
- Time: 10 minutes
- You need: An admin or owner account to save the settings
Steps
Set the rules
Open AI & Answers → AI Guardrails. Choose whether the rules apply to every agent in the workspace or to one agent, then fill in allowed topics, blocked topics and banned phrases (one per line) and an optional maximum answer length.
Turn on presets
Never promise refunds, Never offer discounts, Never give legal advice and Never give medical advice. Each is written into the AI's instructions and also checked against what the AI actually wrote.
Decide what happens on a decline
Write a decline message, then choose: just send the message, offer a "Talk to a person" button, or hand the visitor to a teammate.
Choose who approves each action
In AI & Answers → AI Tools, every action has an approval mode: Runs automatically, Visitor confirms first, or A teammate approves. Teammate approvals show in the inbox with Approve and Reject; the approval timeout (default 15 minutes) is set on the AI Guardrails page.
Test before you go live
Test AI answers applies the same guardrails, and Improve AI answers shows how often each rule was hit.
How the rules are applied
Blocked topics: A visitor message that names one is declined before the AI is called. Answers are checked for them too.Allowed topics: The AI declines questions outside them. An agent's own list replaces the workspace list.Banned phrases and presets: Checked on every answer before the visitor sees it; workspace and agent rules add together.Maximum answer length: 50 to 4000 characters. A longer answer is cut at a sentence boundary rather than declined; the tighter of workspace and agent limits wins.Default approvals: Your own HTTP tools: GET runs automatically, other methods need the visitor's confirmation. Built-in actions that change something (capture contact details, create a ticket, notify Slack, collect details, escalate to a helpdesk, book a meeting time) default to visitor confirmation.Approval timeouts: Teammate approvals expire after the timeout (1 to 1440 minutes) and the visitor is offered a person. Visitor confirmations expire after 24 hours.
Good to know
- While guardrails are on, answers are not streamed, so a draft can never reach the widget before it is checked.
- A gated action never runs on the AI's request alone: ZChat saves the exact arguments, waits for the decision, and runs the action at most once.
- Channels that cannot show a confirm card (anything but the website widget) turn a visitor confirmation into a teammate approval.
- Every tool run is logged with its arguments, result, who decided and when. Guardrail hits record the rule, never what the visitor wrote.
Guardrails narrow what the AI says; approvals control what it does. Most teams start with presets and teammate approval for anything that writes data.