DLP Rules Editor
Supported modes: Hosted Available in: Solo Teams -- View pricing
DLP rules are the core admin lever for blocking sensitive content
from leaving developer machines, the LLM gateway, and (soon) the
browser extension. This guide walks through the dashboard
workflow end-to-end. For the API contract see the
/api/orgs/{id}/dlp/rules family of endpoints documented in the
backend OpenAPI spec.
What a DLP rule is
A DLP rule has six fields:
| Field | Type | Notes |
|---|---|---|
name | string | Human-readable label, shown in audit logs. Required. |
pattern | string (RE2) | Compiled at insert time. PCRE features rejected. Required. |
category | enum | pii / secret / ip / financial / compliance / custom. Required. |
action | enum | detect / mask / block. Required. |
scopes | string[] | Any combination of sdk, gateway, browser_ext, scout. Required. |
enabled | bool | Defaults to true. A disabled rule is invisible to enforcement. |
A rule lives in a lifecycle state machine:
draft -> tested -> impact_previewed -> [pending_approval] -> live
|
+-> disabled
A new rule starts in draft. You can move it to live directly,
or route through the optional approval queue for high-impact rules.
Only live rules are enforced by the SDK / gateway / browser
extension.
Writing your first rule
Open Governance → DLP Rules in the dashboard. Click New rule.
Pattern syntax
Patterns must be RE2-compatible. Most regular regexes work, but the following PCRE features are NOT supported:
- Lookaheads:
(?=foo),(?!foo) - Lookbehinds:
(?<=foo),(?<!foo) - Backreferences:
\1,\2 - Possessive quantifiers:
*+,++
If you paste a PCRE pattern, the test affordance immediately shows the compile error inline. Fix it before saving.
Common patterns
US Social Security Number:
\b\d{3}-\d{2}-\d{4}\b
Email address (loose):
[\w._%+-]+@[\w.-]+\.[A-Za-z]{2,}
AWS access key:
AKIA[0-9A-Z]{16}
Credit card (Visa):
\b4\d{3}[\s-]?\d{4}[\s-]?\d{4}[\s-]?\d{4}\b
Internal project code names:
\b(Manhattan|Apollo|Voyager|Falcon)\b
Test before saving
The form has a Test pattern affordance. Type a sample input that contains the thing you want to catch:
Customer record:
name: Alice Johnson
ssn: 123-45-6789
cc: 4111-1111-1111-1111
Click Test pattern. The backend compiles your regex and reports:
compiles: true | false— if false, the error message points to the exact column.matched: true | false— whether the sample triggered.matches: [...]— up to 10 matched substrings, in order.
Iterate until the matches look right. Remember:
- Greedy is the default. Use
?after a quantifier (.*?) for non-greedy. \bis your friend. Word boundaries prevent4111from matching inside4111111111(which would be a 16-digit card).- Anchor when you can.
^and$are cheap and prevent false positives.