Agent Guardrails → Settings. Click Save settings after changes; every change is recorded in the audit log (changed keys only).
| Setting |
Default |
Notes |
| Emergency kill switch |
Off |
“Block every governed agent action immediately.” See Kill switch. |
| Govern all ability executions |
Off |
Off: only AI agents are governed — application-password and MCP calls, the AI Agent role, and the Site AI. On: logged-in humans are governed too, using the unknown-agent defaults. |
| Defaults for unknown agents |
Read: Allow · Write: Deny · Financial: Deny · Destructive: Deny |
Allow or Deny per risk level. Applies to agents you have not mapped, and to agents set to “Use risk defaults”. |
| Setting |
Default |
Edition |
| Extra keys to redact |
none |
Free. Comma-separated field names whose values are never logged (up to 100; lowercase letters, numbers, _ and -), matched anywhere in a field name. Passwords, tokens, keys and card data are always removed, and emails, phones and addresses are always masked. |
| Audit log retention (days, 1–365) |
30 |
Free. A daily background job deletes older entries. |
| Approval requests expire after (hours) |
24 |
Pro. 1–336 (14 days). |
| Notify these emails about new approvals |
the site admin email |
Pro. Comma-separated. |
| Slack incoming webhook URL (optional) |
none |
Pro. Must be a https://hooks.slack.com/ URL — any other URL is discarded and removes the saved webhook. Once saved it is never shown again; leave the field empty to keep it. |
Shown under the notification settings. Alerts go to the same email addresses and Slack webhook. See Alerts.
| Setting |
Default |
Notes |
| Alert when one agent is denied this many times |
10 |
0 turns the alert off. |
| Alert when one agent makes this many calls |
0 (off) |
0 turns the alert off. |
| Period for both alerts (minutes) |
10 |
1–1440. |
| Setting |
Default |
Notes |
| Let shop managers manage Raqvio Agent Guardrails |
Off |
Shop managers can then use every Raqvio Agent Guardrails screen, but never approve agent actions. |
| Delete all Raqvio Agent Guardrails data when the plugin is uninstalled |
Off |
See Install & requirements. |
Below the settings: the credential & exposure hardening checklist.