# Check your agent's protections before publishing

URL: https://aihio.ai/en/help/ai-agent/safety\
Description: Test content guardrails, restrict installation to the correct domains and choose how to handle verified users and personal data.

Protections address different questions: what the agent handles, where the widget works and whose data an action may use. Check these separately before customer use.

## Choose protection for the task

| What you need to check                                                           | Start here                                         | Verification                                       |
| -------------------------------------------------------------------------------- | -------------------------------------------------- | -------------------------------------------------- |
| The agent handles harmful messages or instruction-bypass attempts appropriately. | Settings → AI → Content Safety                     | Test guardrails and an ordinary customer question. |
| The widget works only on your websites.                                          | Settings → Security                                | Test on an allowed domain and another domain.      |
| An action uses the correct signed-in customer's details.                         | Identity verification and the action's permissions | Test with a verified and an unverified customer.   |
| Contact details are collected as agreed.                                         | Lead collection fields, consent and privacy link   | Check the visible form and saved details.          |

## Configure and test content guardrails

1. **Enable guardrails**

   Open the agent's **Settings → AI → Content Safety**. Check **Enable
   guardrails** and choose **Show the standard safety message** or **Show your
   own message** for a blocked message.
2. **Write your message if needed**

   Write a **Custom message** that explains the agent's task and the customer's
   next available step. Save settings and wait for confirmation.
3. **Try the protection**

   Open **Test guardrails**, enter a **Message to test** and choose **Test**.
   Try an ordinary customer question and a message asking the agent to bypass
   its instructions. The test does not change settings or consume message
   credits.
4. **Verify the conversation too**

   Test the agent in a normal preview conversation with the saved settings.
   Check that allowed questions still get useful answers and blocked cases give
   customers a clear next step.

> **Note — The test does not enable protection:**
>
> With guardrails disabled, the test shows what would happen if they were
> enabled. A personal-data finding in the test does not itself block a message.
> The Coming Soon custom-rules view is not an available rules editor. Verify
> activation in the saved settings.

## Restrict installation domains

Open **Settings → Security**, enable domain restriction and enter **Allowed domains**, one name per line. Add `example.com` and `www.example.com` separately if you use both. These are example addresses; replace them with your own domains. Save and test on the website rather than only in the dashboard preview.

Domain restriction does not identify a signed-in user. For an action such as looking up a customer's own order, configure [identity verification](/en/help/ai-agent/identity-verification) and ensure the receiving API checks access to the requested data. An order number typed into the conversation is not authorization.

## Captured data and access removal

Collect only the details needed for the task. Check [lead collection](/en/help/ai-agent/lead-collection) consent and privacy settings and your organization's approved handling before publishing the form.

Pausing an agent, removing installation code and removing workspace membership are different from deleting personal data already saved. The [account and workspace guide](/en/help/account/settings#data-handling-and-deletion-requests) provides maintained privacy sources and the data-request process.

## If the test fails

| Observation                                            | What to check next                                                                                        |
| ------------------------------------------------------ | --------------------------------------------------------------------------------------------------------- |
| The guardrail test fails or reports too many requests. | Read the error, wait if needed and retry. Failure does not establish that a message is allowed.           |
| The widget does not open on your website.              | Check the actual domain, saved restriction and [installation troubleshooting](/en/help/ai-agent/publish). |
| An action cannot get the customer's data.              | Check identity verification and the receiving API's permissions.                                          |
| An ordinary question gets no useful answer.            | Check sources, instructions and the protection message, then retest the change.                           |

## Credit balance, sending rate and personal-data warnings

Message-credit balance describes how much service the workspace can use. Sending-rate limits protect a different boundary: messages sent too quickly. If the widget asks the visitor to wait, wait before retrying. Do not disable protection or issue parallel retries to work around the error.

A personal-data warning in the message field advises the visitor; it does not automatically block sending. Check your data-collection policy and visible privacy information. A guardrail-test detection, a message-field warning and your organization's data-request process are separate things.
## Next steps

- [Publish](/en/help/ai-agent/publish) — Publish an AI agent as a chat widget or an embedded conversation.
- [Identity verification](/en/help/ai-agent/identity-verification) — Pass server-signed user information and choose the right verification method for your chat window.
- [Account and workspace settings](/en/help/account/settings) — Manage your own settings and distinguish them from shared workspace settings.
