Guardrails for AI Applications

Design and implement guardrails for LLM-based and agentic applications from prompts through runtime. Guardrail fundamentals cover the risk landscape from prompt injection through data leakage and...

Read More
8781  Reviews star_rate star_rate star_rate star_rate star_half
$2,000USD
Duration 2 days
Course Code GAI-2502
Available Formats Classroom

Overview

Course Description

Design and implement guardrails for LLM-based and agentic applications from prompts through runtime. Guardrail fundamentals cover the risk landscape from prompt injection through data leakage and jailbreaks, threat modeling with MITRE ATLAS, guardrail categories of input/output filtering and policy enforcement, where guardrails live across prompts, code, and infrastructure, the strictness-versus-usability tradeoff, and defense-in-depth planning. Prompt-level, code-level, and agentic guardrails cover system and developer messages as constraints, structured prompts and templates, refusal and escalation patterns, prompt-injection mitigation, context isolation, input and output validation, content safety integrations, allow and deny lists, role restrictions, structured output enforcement, tool-access constraints, memory and retention guards, and supervision of planning and execution. Testing, monitoring, governance, and operationalization cover effectiveness metrics, logging, drift detection, audit hooks, alignment with policies and regulations, documenting strategies, human-in-the-loop review, roadmap planning, and incident response. Hands-on labs produce a broken unguarded agent baseline, an adversarial-prompt test suite, a guardrail test harness, and a human-in-the-loop approval workflow. The course is designed for cybersecurity professionals, DevOps engineers, software developers, and data scientists deploying LLM-based and agentic applications.

Skills Gained

By the end of this course, participants will be able to:

  • Articulate key categories of risks in LLM and agentic applications
  • Configure prompt-level and system-level guardrails for specific use cases
  • Implement runtime guardrails using popular frameworks and SDKs
  • Apply guardrails around tool use, memory, and planning in agentic workflows
  • Iteratively test guardrails in production-like environments

Who Can Benefit

  • Cybersecurity
  • DevOps
  • Software Developers
  • Data Scientists

Prerequisites

Participants should enter this course with:

  • Comfort writing Python code and working in developer interfaces
  • Practical cybersecurity experience and/or a major cybersecurity certification (e.g., Security+, CISSP)
  • Foundational knowledge of generative AI, prompt engineering, RAG, and GenAI development patterns (covered by GAI-1101 or similar)

Organizational Objectives

This course assists organizations to:

  • Reduce AI-incident likelihood through layered guardrails and defense-in-depth
  • Establish auditable guardrail telemetry that supports regulatory reporting
  • Lower review-cycle cost by codifying refusal and escalation patterns at prompt and policy levels
  • Build a working guardrails vocabulary across security and development teams

Software

All attendees must have a modern web browser and an Internet connection.

Course Details

Course Details

Guardrails Fundamentals for LLM and Agentic Systems

By the end of this module, you will be able to map the risk landscape of LLM and agentic applications, threat-model with MITRE ATLAS, choose between guardrail types and locations, and plan defense-in-depth for AI systems.

  • Risk landscape: prompt injection, data leakage, jailbreaks
  • Threat modeling with MITRE ATLAS
  • Types of guardrails: input/output filtering, policy enforcement
  • Guardrail locations: prompts, code, infrastructure
  • Tradeoffs: strictness vs. usability
  • Defense-in-depth planning
  • Hands-on Lab: Map risks for a sample AI app and break an unguarded agent to expose its weakest defense.

Prompt-Level Guardrails and System Prompts

By the end of this module, you will be able to use system and developer messages as constraints, design structured prompts and templates, write refusal and escalation patterns, reduce prompt-injection risk, and apply context-isolation strategies.

  • Using system and developer messages for constraints
  • Structured prompts and templates
  • Prompt patterns for refusal and escalation
  • Reducing prompt injection risk
  • Context isolation strategies
  • Hands-on Lab: Design guarded prompts for one application and test them against an adversarial prompt set.

Content and Policy Guardrails in Code

By the end of this module, you will be able to implement input/output validation and policy checks, integrate content safety tools, layer policies (allow/deny lists, role restrictions), and handle violations through messaging, logging, and escalation.

  • Input/output validation and policy checks
  • Integrating content safety tools
  • Policy layers: allow/deny lists, role restrictions
  • Handling violations: messaging, logging, escalation
  • Structured output enforcement
  • Hands-on Lab: Implement content filters around one LLM API and enforce structured output with rejection logic.

Guardrails for Agentic Workflows (Tools, Memory, and Planning)

By the end of this module, you will be able to recognize agentic-system risks (tool use, memory, planning), apply ATLAS case studies, constrain tool access and usage, guard memory and retention, and supervise planning and execution.

  • Risks in agentic systems: tool use, memory, planning
  • ATLAS case studies and threat patterns
  • Constraining tool access and usage
  • Guardrails for memory and retention
  • Supervising planning and execution
  • Hands-on Lab: Constrain an agent’s tool use and implement memory and planning guardrails on the same agent.

Testing, Evaluating, and Monitoring Guardrails

By the end of this module, you will be able to design and automate guardrail tests, choose effectiveness metrics, log and monitor guardrail events, detect guardrail drift, and integrate observability and audit hooks.

  • Designing and automating guardrail tests
  • Metrics for effectiveness: block rates, false positives
  • Logging and monitoring guardrail events
  • Guardrail drift and evaluation
  • Observability and audit hooks
  • Hands-on Lab: Build a guardrail test harness and tune thresholds for a production-style deployment.

Governance, Compliance, and Operationalization

By the end of this module, you will be able to align guardrails with policies and regulations, document strategies and responsibilities, implement human-in-the-loop review, plan guardrail roadmaps, and respond to security incidents.

  • Aligning guardrails with policies and regulations
  • Documenting strategies and responsibilities
  • Human-in-the-loop review patterns
  • Roadmap for evolving guardrails
  • Secure handling and incident response
  • Hands-on Lab: Create a guardrail runbook and rollout plan, then implement a human-in-the-loop approval workflow.

Schedule

FAQ

Does the course schedule include a Lunchbreak?

Classes typically include a 1-hour lunch break around midday. However, the exact break times and duration can vary depending on the specific class. Your instructor will provide detailed information at the start of the course.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

Does Ascendient Learning deliver group training?

Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.

What does vendor-authorized training mean?

As a vendor-authorized training partner, we offer a curriculum that our partners have vetted. We use the same course materials and facilitate the same labs as our vendor-delivered training. These courses are considered the gold standard and, as such, are priced accordingly.

Is the training too basic, or will you go deep into technology?

It depends on your requirements, your role in your company, and your depth of knowledge. The good news about many of our learning paths, you can start from the fundamentals to highly specialized training.

How up-to-date are your courses and support materials?

We continuously work with our vendors to evaluate and refresh course material to reflect the latest training courses and best practices.

Are your instructors seasoned trainers who have deep knowledge of the training topic?

Ascendient Learning instructors have an average of 27 years of practical IT experience and have also served as consultants for an average of 15 years. To stay current, instructors spend at least 25 percent of their time learning new, emerging technologies and courses.

Do you provide hands-on training and exercises in an actual lab environment?

Lab access is dependent on the vendor and the type of training you sign up for. However, many of our top vendors will provide lab access to students to test and practice. The course description will specify lab access.

Will you customize the training for our company’s specific needs and goals?

We will work with you to identify training needs and areas of growth.  We offer a variety of training methods, such as private group training, on-site of your choice, and virtually. We provide courses and certifications that are aligned with your business goals.

How do I get started with certification?

Getting started on a certification pathway depends on your goals and the vendor you choose to get certified in. Many vendors offer entry-level IT certification to advanced IT certification that can boost your career. To get access to certification vouchers and discounts, please contact info@ascendientlearning.com.

Will I get access to content after I complete a course?

You will get access to the PDF of course books and guides, but access to the recording and slides will depend on the vendor and type of training you receive.

How do I request a W9 for Ascendient Learning?

View our filing status and how to request a W9.

Reviews

Course was thorough and gave a very solid grounding in the tools advertised.

As long as you keep Holly as an instructor, I will always come back to learn.

Easy to use and exactly what I was looking for. Value for money was exceptional.

I was very pleased with the course setup by ExitCertified and the instructor.

The training was good but needed the basic skills of maximo before getting deep in the configuration of it.