Scanner & Governance
The Scanner & Governance page controls how CleverGuard inspects every message flowing through your agents — what it detects, how hard it looks, and what happens when something is found. Changes apply immediately to every agent in your organization.
The CleverGuard pipeline
Every message sent to or received from an agent passes through a tiered scanning pipeline before it is forwarded. Tiers 1 and 2 run on every plan; the Tier 0 data-label gate is Enterprise-only. Each tier runs in sequence; a high-confidence finding at an early tier short-circuits the later ones so you only pay latency for what is needed.
What the settings page controls
- Tier 3 card — an informational card describing the self-hosted contextual judge. There is nothing to enable, no provider picker, and no customer Tier 3 key path.
- Drift observation threshold — how many observations an auto-discovered agent needs before drift enforcement applies to it. Per-category scanner strictness (PII, injection, secrets, toxicity, URL blocking) is not set here; it comes from each agent's guardrail profile.
- Detection response — choose whether a detection triggers Visibility (log only), Notify (log + email admins), or Enforce (block the request or restrict the agent).
- ClaimGuard output verification — verify that agent responses are grounded in the source context. Flags unsupported or contradicted claims and records the evidence. Disclosure: the claim extractor runs on Clevername-operated, self-hosted compute that Clevername pays for — not on your provider key and not on a third-party model API. The evidence spans it stores are encrypted with your key when you have zero-knowledge I/O encryption on.
Open Scanner & Governance
Navigate to Settings → Scanner. The Tier 3 card near the top of the page explains the current self-hosted beta governance-compute behavior. It is read-only: Tier 3 is not something you switch on or off.
Check availability
Tier 3 is operated by Clevername, not by a customer BYOK provider. If the backend endpoint is unavailable, scan results surface reduced coverage rather than silently pretending the contextual judge ran.
Confirm key separation
Your normal agent and chat calls still use your configured provider keys. Tier 3 does not read those keys, does not spend them, and does not fall back to a managed provider if the self-hosted judge is unavailable.
Use response modes for enforcement
Tier 3 contributes findings to the same Visibility, Notify, and Enforce response modes as the rest of CleverGuard. Use Enforce only after you have reviewed alert volume.
Monitor reduced coverage
If Tier 3 cannot run, downstream surfaces show reduced coverage signals such as ml_degraded. Treat those as an operational signal, not a clean Tier 3 verdict.
Detection response modes
Choose how CleverGuard responds when it detects a threat across your org: