Groundskeeper
A gateway-neutral AI guardrails decision service.
Groundskeeper evaluates LLM inputs and outputs against immutable policy snapshots. It returns a deterministic verdict, findings, optional transformations, and explicit coverage gaps. Portkey is the first gateway adapter, not the service boundary.
This site renders the Markdown and MDX files in the repository's docs/
directory. Those files are the source of truth; edit them there, not here.
How a decision is made
A gateway or application sends an event for evaluation and applies the returned decision. Groundskeeper does not proxy model traffic.
- Detectors report evidence. Policy composition alone decides
alloworblock. - Missing coverage is
unjudged, never silently treated as clean. - Policies compile ahead of evaluation into immutable, digest-addressed snapshots.
- Sensitive values are absent from ordinary logs and audit records.
Where to start
- Architecture overview: system boundaries and data flow.
- Policy bundle specification: how policies are authored and compiled.
- Detector and plugin contract: how detectors extend the service.
- Threat model: what the design defends against.
- Implementation plan: the phased delivery sequence.
- Open decisions: choices that still need an owner.
Contracts and status
Decisions and their rationale are recorded as architecture decision records. The HTTP contract is the OpenAPI document, and the canonical data contracts are the JSON Schemas.
Everything under api/ is an initial v1 draft. Compatibility guarantees begin
only when an ADR records that a contract has been frozen. Examples use synthetic,
non-sensitive data. To run the first executable slice, see the
repository README.