Skip to content

Exceptions

Sometimes a guardrail is right for the organization and wrong for one team. The legal team reviews contracts full of client names; the billing team works with account numbers all day. Weakening the guardrail for everyone is the wrong fix.

Exceptions let you carve out exactly who is exempt, from what, where, and for how long — with a reason attached. They live on the Exceptions page at app.sanitized.ai.

What an exception does

While an exception applies, the covered guardrails switch to silent monitoring for that person: their prompts send with no banner, and the detection is still logged.

That last part matters. An exception relaxes enforcement — it does not create a blind spot. Your Events page and reports still show what was detected, so an auditor asking “what happened to this data?” still gets an answer.

Creating one

Click New Exception and fill in five things:

  1. Who — a specific user, or a whole department. Department matching is case-insensitive, and follows the department set on each user’s profile.
  2. Which guardrails — all of them, or a specific list.
  3. Which AI tools — all of them, or specific ones. Useful when a team needs an exemption on your sanctioned enterprise tool but not everywhere.
  4. Expiry — a date, or permanent. It defaults to 30 days out, because time-boxed is the healthier habit: an exception that expires forces a deliberate renewal instead of quietly living forever.
  5. Reason — required. This is what makes the exception defensible six months later.

Every exception records who created it and when. Creating and revoking are both written to your audit log.

Keeping them under control

The top of the Exceptions page shows three counts: active, expiring within 7 days, and expired. Anything expiring soon is badged in the table so it doesn’t lapse without you noticing.

Expired exceptions stop applying on their own — there’s nothing to clean up, and full enforcement resumes automatically. They stay in the list for the record.

To end one early, use Revoke. Enforcement resumes immediately.

Exceptions vs. changing the guardrail

Use an exception when the guardrail is correct but a specific group has a legitimate need. Change the guardrail itself when it’s firing on things that aren’t actually sensitive — in that case the guardrail is wrong for everyone, and an exception just hides the problem for one team.

The Overrides card on the Events page helps you tell the difference: if everyone is overriding a guardrail, it needs fixing, not exempting.