pi + Guardrails
pi runs the task; the Guardrails connector supplies only the operations and resources allowed by the account you authorize. The Composer selects pi, asks for Guardrails access before sending, and keeps both choices in one task draft.
How the combination works
pi plans and executes. Guardrails supplies authorized app access.
Pi runs a compact coding and tool-use loop that can inspect files, execute commands, and iterate on a bounded task.
Putting the Sec in DevSecOps: Simplify Application Security
pi
Owns the task loop, model calls, cloud computer, tool choices, progress and final result.
Guardrails connector
Supplies the currently exposed operations for the authorized Guardrails account. It does not promise every feature in the Guardrails product.
Permission boundary
The connected identity, granted provider scopes, organization policy, resource sharing and the task's explicit instruction all constrain what pi can do.
Setup and first task
Connect one Guardrails account and verify one known resource.
The Composer preselects pi with GPT-5.6 Sol. Start read-only when possible, then expand to write operations only after the account and resource boundary are clear.
Open the pi Composer
The Composer above carries pi, GPT-5.6 Sol, and Guardrails. Add a precise target and expected result; the draft stays on this page during sign-in or connector authorization.
Authorize the intended Guardrails account
Review the Guardrails account, workspace and permissions on the authorization screen. Your organization's policies or administrator approval may limit which resources the connection can access.
Run and verify a bounded task
Name one Guardrails resource you can already access and ask the agent to check whether a read operation is available. If it is, retrieve and summarize that resource without changing it. If it is not, ask the agent to explain the missing operation or permission. Open the same resource in Guardrails and compare it with the agent's result. Check the account, resource identifier and current content before using the output for another task.
Access, cost and limits
What to verify before scaling pi + Guardrails
Focused engineering tasks where a lightweight agent loop and quick iteration matter more than a large orchestration layer.
Establish with the first run
- pi and GPT-5.6 Sol remain selected after sign-in.
- Guardrails shows the intended connected account before the task is sent.
- The returned data matches one known source resource, with write actions excluded until separately authorized.
Still depends on your setup
- A catalog listing does not guarantee every Guardrails website feature is available as an agent operation.
- OAuth scopes do not replace organization policy, resource sharing or a precise task instruction.
- Total task cost can include model tokens, active computer time, paid tools, connectors and the provider's own plan or quota.
Verification and recovery
Check Guardrails itself before trusting the result.
Open the same resource in Guardrails and compare it with the agent's result. Check the account, resource identifier and current content before using the output for another task.
Connection troubleshooting
If Guardrails access fails, check the connected identity, resource sharing and requested permissions. Reconnect an expired or revoked account in connector settings. If the connection is healthy but an operation is unavailable, changing accounts may not resolve it.
Writes need explicit scope
Name the target record and exact allowed change. A request to summarize, analyze or draft does not authorize sending, publishing or deleting.
Re-check current state
For decisions or follow-up writes, open the resource in Guardrails and check its current state. A successful earlier read may already be stale.
Common questions
Related resources
