Model Boundary
Allow an AI agent to call only the models you list. Model Boundary denies the call, or moves it to a fallback model, before the provider is called.
Real-Time(Preventive)Checked before the call runs, so it can stop it
You allow gpt-4o-mini. The agent asks for gpt-4o. Model Boundary either denies that call or swaps it to a fallback model you chose. The model name on the request is the only thing it reads.
Runs On
The SDK and the Gateway
You Set
The models the agent may call. Optionally a fallback model.
Your Agent Sends
Nothing extra
What Happens
| Model on the call | With Block on |
|---|---|
| On your allowlist | The call runs. |
| Not on the list, and you named a fallback | The call continues on the fallback model. |
| Not on the list, and there is no fallback | The call is denied. |
Observe records the match and lets the call through. Warn does the same and marks what would have happened. Only Block changes or stops the call.
Set It Up
- In the app, open Policies and click Create Policy.
- Choose Model Boundary.
- List the Allowed Models. Optionally pick a Fallback Model.
- Set the mode to Block, then click Activate Policy.
In code, wrap your agent with govern(). For apps that cannot use the SDK, point your model client at the Gateway.
Good To Know
- Model Boundary stops the call that is about to happen. The After Run Allowed Models policy only records a violation once the call has already run.
Next Steps
© 2026 Traccia.