This page is machine-translated from French. Read the French original.
Content control
Content control applies rules to user messages and assistant responses. It serves to enforce an internal policy: preventing the entry of data that has no place in a conversation, masking sensitive information, excluding topics outside the scope.
Function disabled by default.
Réglages → Contrôle de contenu.
How is a rule defined?
Each rule includes:
- A name, which appears in the monitoring of offences; ;
- A pattern : either a comma-separated list of terms, or a regular expression for structured cases; ;
- a breakage sensitivity, can be activated; ;
- a scope : incoming messages, outgoing replies, or both; ;
- a action.
The shares
To block. The message is rejected and an explanation message is displayed. Nothing is passed to the model.
Hide. The corresponding passages are replaced with a masking mark, and processing continues. This is useful for allowing a question to pass while removing sensitive data.
Report. Processing continues normally, but the occurrence is logged. This is a good way to test a rule before actually applying it.
Write useful rules
By list of terms
Each term is searched as a whole word — so a short term will not trigger on a syllable within another word. A term containing spaces is searched as a complete phrase.
Suitable for vocabulary: confidential project names, internal designations, topics outside scope.
By regular expression
Suitable for formats: structured numbers, internal identifiers, standardized references, email addresses of a given domain.
An invalid expression is not applied. Test your patterns, and start with the action. Report to observe what they actually capture before blocking.
The displayed message
A default message explains that content has been blocked by the organization's policy. This message is customizable at the instance level, and each rule can also carry its own message.
Write it for a user, not for an administrator. «"This message contains data that should not be entered here. Contact department X for further instructions" is helpful; "Violation of rule 7" is not.
Monitoring of offences
Each trigger is logged with the relevant rule, the user, the date, and a short excerpt of context — never the entire message.
This monitoring allows us to:
- identify a rule that is too wide and hinders the work; ;
- spot a ruler that is too narrow and lets through what it should catch; ;
- document the incidents.
What content control is not
This is not protection against exfiltration. A determined user bypasses a pattern-based filter. Content control is used to prevent errors, not the intentions.
This is not a semantic moderation. It operates on patterns, not on meaning. A roundabout way of phrasing works.
This is not a substitute for access rights. What shouldn't be seen shouldn't be in the workspace. → Users and roles
Recommended implementation
- Start by observing. Create your rules in action Report and let it run for a few days.
- Analyze the tracking. How many triggers? Legitimate or false positives?
- Adjust the patterns, then proceed to Hide Or To block.
- Communicate. A blocking rule that is unknown to users is experienced as a failure.
- Re-examine periodically. An organization's vocabulary evolves.
