ar-guardrail-deployer
Installation
SKILL.md
AR Guardrail Deployer
Overview
A guardrail enforces an AR policy at runtime. Deployment is two steps: (1) snapshot the tested DRAFT into an immutable numbered version, (2) attach that version to a guardrail (create or update) with the required cross-region guardrail profile. Updating DRAFT later won't affect a guardrail pinned to a number.
Reference: ../../shared/references/ar-api-context.md (deployment section).
Key directives
- Version before deploying.
CreateAutomatedReasoningPolicyVersionneeds the currentdefinitionHash(concurrency token) from a get/create/update response. The script fetches it. - Pin guardrails to a numbered version in production, not DRAFT.
- ⚠️ AR guardrails require a
crossRegionConfig(a guardrail profile, e.g.us.guardrail.v1:0). The script derives the profile ARN from the policy ARN's account+region. - ⚠️ Max 2 AR policies per guardrail.
- Confirm before deploying. This is an outward-facing change. Check what an existing guardrail currently points to before you overwrite it.
- Default
confidenceThreshold= 1.0 (most stringent). Lower only with a tested reason.