Scanner & Governance
The Scanner & Governance page controls how CleverGuard inspects every message flowing through your agents — what it detects, how hard it looks, and what happens when something is found. Changes apply immediately to every agent in your organization.
The CleverGuard pipeline
Every message sent to or received from an agent passes through a four-tier scanning pipeline before it is forwarded. Each tier runs in sequence; a high-confidence finding at an early tier short-circuits the later ones so you only pay latency for what is needed.
What the settings page controls
- Tier 3 escalation — enable the optional self-hosted contextual judge when available. There is no provider picker or customer Tier 3 key path.
- Content safety rules — toggle individual scanner categories (PII, injection, secrets, toxicity, URL blocking) and set each to standard or strict mode.
- Detection response — choose whether a detection triggers Visibility (log only), Notify (log + email admins), or Enforce (block the request or restrict the agent).
- ClaimGuard output verification — verify that agent responses are grounded in the source context. Flags or blocks unsupported or contradicted claims before they reach users.
Open Scanner & Governance
Navigate to Settings → Scanner & Governance. The Tier 3 card explains the current self-hosted beta governance-compute behavior near the top of the page.
Check availability
Tier 3 is operated by Clevername, not by a customer BYOK provider. If the backend endpoint is unavailable, scan results surface reduced coverage rather than silently pretending the contextual judge ran.
Confirm key separation
Your normal agent and chat calls still use your configured provider keys. Tier 3 does not read those keys, does not spend them, and does not fall back to a managed provider if the self-hosted judge is unavailable.
Use response modes for enforcement
Tier 3 contributes findings to the same Visibility, Notify, and Enforce response modes as the rest of CleverGuard. Use Enforce only after you have reviewed alert volume.
Monitor reduced coverage
If Tier 3 cannot run, downstream surfaces show reduced coverage signals such as ml_degraded. Treat those as an operational signal, not a clean Tier 3 verdict.
Detection response modes
Choose how CleverGuard responds when it detects a threat across your org: