Skip to main content

Overview

Guardrails set the default handling for MCP servers and skills that aren’t in your Catalog. Items in the Catalog follow their own access controls instead. The page has two settings: For each setting, choose a Default action:
  • Allow: Formal lets the traffic through and logs it. New items appear in Shadow AI for review.
  • Block: Formal blocks the traffic. For unknown MCP servers, the agent receives a list of approved alternatives. For unknown skills, the user sees Formal’s standard block message.
Changing settings requires the Policies permission.

Configure a Guardrail

1

Open Guardrails

Go to Guardrails.
2

Choose the default action

Under Unknown MCPs or Unknown Skills, select Allow or Block.
3

Write the block message (optional)

With Block selected, enter Message shown to blocked users. Formal stores it as the policy’s reason, which appears in Logs. Users don’t see this text yet: they get the alternatives list or Formal’s standard block message.
4

Save

Click Save Changes.
Verify: Go to Policies. With Block selected, you see Block unknown MCPs or Block unknown skills.

What Formal Creates

Each guardrail set to Block is a generated policy. Selecting Allow removes it.

Block Unknown MCPs

The policy blocks MCP tool calls to servers that have no Formal Resource:
The mcp_suggest_alternatives block tells the agent which approved MCP servers it can use instead. It also explains how to request the blocked server. See Suggest approved MCP alternatives. Only the Formal Endpoint sees MCP servers that have no Formal Resource. This guardrail applies on devices that run the Endpoint with Transparent Mode.

Block Unknown Skills

The policy blocks LLM requests that load a skill whose name is not in an approved list:
approvedSkills holds the names of the managed skills in your Catalog. Formal updates the list when someone with the Policies permission opens the Catalog, Shadow AI, or Guardrails page. Formal detects loaded skills in Claude Code traffic only, so this guardrail doesn’t affect other agents. It names each loaded skill after the folder that holds its SKILL.md.
Change guardrails from the Guardrails page, not in the policy editor. Saving a guardrail rewrites its generated rules. See Policy Tags to recognize generated policies.

Troubleshooting

Cause: The traffic doesn’t pass through the Formal Endpoint, or the server has a Formal Resource. Fix: Confirm that a network rule intercepts mcp traffic on the device. Servers with a Formal Resource follow their Catalog access controls.
Cause: The skill’s access controls exclude the user. Fix: Open the skill in the Catalog and check Access Controls.

Next Steps

Shadow AI

Review items that people already use

Access Requests

Approve employee requests for blocked MCP servers