Skip to main content
Guardrails are at the core of Corridor’s approach—they are security rules and best practices that Corridor enforces in your code. Guardrails give AI coding agents the context they need to write secure code from the start, proactively ensuring that vulnerable patterns are never introduced. Guardrails also run as checks on code diffs in pull requests—if code in a PR violates a guardrail, Corridor catches it and flags it for review.

Why guardrails matter

Traditional security tools run after code is committed—by then, the vulnerability exists and requires remediation. Corridor’s guardrails shift security left by integrating directly into the AI code generation process:
  • Prevention over detection: Security context guides the AI to avoid vulnerable patterns
  • Zero developer friction: No separate security review step—it happens during coding
  • Reduced remediation costs: Fixing a vulnerability before it’s written costs nothing

How guardrails work

Guardrails operate through MCP and Hooks, which allow Corridor to participate in AI interactions:
  1. Developer prompts AI: “Write a function to query the database”
  2. Corridor analyzes context: Project type, existing code patterns, security policies
  3. Security context provided: Guardrails inform the AI about relevant risks (e.g., SQL injection, parameterized queries)
  4. AI generates secure code: The response incorporates security best practices
  5. Activity logged: The interaction is recorded for audit and analytics
Guardrails function at two levels:
  • During code generation: Guardrails provide additional context to AI models (via MCP) so the AI avoids insecure suggestions. This happens invisibly as you code
  • During code review: Guardrails run as checks on code diffs in pull requests. If code in a PR violates a guardrail, Corridor catches it and flags it for review

Configuring guardrails

By default, Corridor applies the Corridor Default Security Pack: a comprehensive pack of essential security guardrails covering common vulnerability classes including injection attacks, authentication issues, and access control flaws. Corridor also provides pre-loaded security packs tailored to specific languages, app types, and standards. Teams can create custom packs on the Guardrails page comprised of guardrails unique to their needs. See Configuring Guardrails for detailed instructions on setting up default packs, custom guardrails, and custom context.

Guardrail versioning

Guardrail versioning is in private beta. Corridor must enable it for your team.
Guardrail versioning is available in the Corridor app and through MCP. Every edit writes a new version, whether a person, Corridor Agent, or a Scheduled Agent made it. Version history is how you see what changed and restore an earlier version.

In the app

When versioning is on, each guardrail shows a vN chip. Click it to open Version history. Each version records:
  • The version number
  • When it was written
  • Who wrote it
  • A short reason
  • The content at that version
Restore this version copies that version’s content onto the live guardrail. Corridor keeps the old versions. Restore writes a new current version. It does not delete history. You cannot restore a version on an archived guardrail. Un-archive it on the dashboard first, then restore.

Through MCP

Owner and Admin can use these tools when versioning is on: getGuardrailVersions is read-only. restoreGuardrailVersion needs custom guardrails on your plan. Standard Users cannot use either tool. See Corridor MCP for the tool list.

Update and archive through MCP

Updating and archiving guardrails through MCP is a separate private beta feature. Corridor must enable it for your team.
You already create and edit custom guardrails in the dashboard. Corridor Agent and Scheduled Agents can write them too. These MCP tools let an AI assistant make the same kinds of writes. Owner and Admin can use these tools. Both need custom guardrails on your plan. Standard Users cannot use them. updateGuardrail is available when versioning is on. archiveGuardrail needs archive enabled as well. There is no MCP tool to un-archive a guardrail. Un-archive it on the dashboard. When archive is on, the dashboard also shows Archive instead of Remove. Archived guardrails stay in history and do not run. An Owner can still permanently delete an archived guardrail. Restore a version does not un-archive a guardrail. See Corridor MCP for the tool list.

Change History

Open Guardrails → Change History to see team-wide edits.
  • By change lists every edit in time order
  • By guardrail groups edits under each guardrail
Use Change History when you want the team audit trail. Use Version history when you want one guardrail’s content over time.

Managing guardrails via AI assistant

If you have the Corridor MCP integration set up, your AI assistant can interact with guardrails directly. Owner and Admin:
  • View guardrails: Ask your AI “What guardrails should I follow?” and it will call getGuardrails
  • Create guardrails: Tell your AI “Create a guardrail for SQL injection prevention” and it will call createGuardrail
Guardrail versioning (private beta):
  • View versions: Ask your AI for a guardrail’s version history and it will call getGuardrailVersions
  • Restore a version: Tell your AI to restore an earlier version and it will call restoreGuardrailVersion
Update and archive through MCP (private beta):
  • Edit guardrails: Tell your AI to update a guardrail and it will call updateGuardrail
  • Archive a guardrail: Tell your AI to archive a guardrail and it will call archiveGuardrail
Standard Users can use analyzePlan only. They cannot list, create, edit, restore, or archive guardrails. See Corridor MCP for the full list of available tools and requirements.

Next steps

Configuring Guardrails

Set up and customize guardrails for your projects

PR Reviews

Automated security reviews on pull requests

Findings

Track and remediate security issues

Scheduled Agents

Private beta. Run Corridor Agent on a schedule or when findings change