Skip to main content

WonderFence Getting Started

Prerequisites​

Before integrating WonderFence, ensure you have the following:

  • A WonderFence account with access credentials provided by your organization administrator.
  • An AI application (chatbot, LLM-powered service, generative AI workflow) that you want to protect.
  • API access to your application's request/response pipeline, allowing WonderFence to inspect traffic.
  • Familiarity with your content policies — an understanding of what types of content you need to detect, block, or redact.

Logging into WonderFence​

  1. You will receive an invitation email with a link to activate your Alice WonderFence account.
  2. Click the link and log in using your email address as the username, then create your own password.
  3. Users with appropriate permissions can define roles and permissions for other users. Administrators can invite new users to the WonderFence account and assign them the roles. An invitation email will be sent to them.
  4. Each account may contain multiple projects, where each project might be intended for an entirely different purpose, for a different team, and/or may handle different content. If your account has multiple projects, you can change the active project by selecting the world icon in the bottom-left corner.

Note — Alice can support Single Sign-On (SSO) logins as an add-on, such as Google login. To add SSO, contact us. Note — Only WonderFence administrators can access all functionality by default. Administrators can define roles and permissions of other users and can invite new users to the account.

Integration Options​

WonderFence supports multiple integration methods to fit your architecture:

MethodDescriptionBest For
REST APISend content directly to WonderFence's evaluation endpoint and receive detection results synchronously.Applications with custom middleware or orchestration layers.
SDKUse the WonderFence SDK (Python or TypeScript) to embed guardrail checks directly in your application code.Teams that want native integration with minimal boilerplate.
IntegrationsPlug WonderFence into the agent framework, runtime or AI gateway you already use, such as LangChain, AWS Strands, LiteLLM or Microsoft Copilot Studio.Rapid deployment with minimal code changes.

Setup steps and code for every integration are in the Integrations section of this documentation.

Setting Up Your First Guardrail Policy​

Step 1 — Browse the Policy Catalog​

  1. Log in to the WonderFence platform.
  2. Navigate to the Enforcement Policies page from the main navigation.
  3. Browse the policy catalog. Policies are displayed as cards organized by group (Security, Privacy, Safety).
  4. Use the filter bar to narrow results by group, risk framework (OWASP, MITRE), or action type.

Step 2 — Configure a Policy​

  1. Click a policy card to open the Policy Editor. The policy's API Response Key is shown under the title — this is the value that identifies the policy in API responses, so use it when matching detections in your integration.
  2. Set the message type: choose whether the policy applies to All messages, Only Prompt (user inputs), or Only Response (AI outputs).
  3. Set the confidence level (shown when enabled for your account): start with Medium for balanced detection, and adjust later based on results.
  4. Set the action:
    • Choose Warn (Detect) if you want to monitor without blocking — recommended for your first policy.
    • Choose Block to prevent violating content from being delivered. Customize the block message, and — where enabled for your account — choose whether it is returned as text or as audio.
    • Choose Redact (Mask) for Privacy policies to replace sensitive data with placeholders. Privacy policies start here, but you can switch them to Warn (Detect) to audit what they would catch without altering any content.
  5. Optionally add keywords for supplementary rule-based detection.

Step 3 — Enable the Policy per Application​

  1. At the bottom of the editor, use the Applications toggles — one row per registered application. Turn a toggle on to apply (enable) the policy for that application; turn it off to stop applying it. A policy runs for an application only while that application's toggle is on.
  2. Click Save Policy.
  3. The policy begins enforcing on new traffic for the enabled applications immediately.

A custom-model policy whose model is still generating cannot be enabled yet — the application toggles are disabled, with a message, until the model is ready.

Note: In accounts that use group application access, the Applications list holds only the applications you can access. Saving the policy changes those and leaves the policy's other applications exactly as they were, so you never switch a policy off for an application outside your access. A policy applied only to applications you cannot access shows no applications at all.

Step 4 — Run a Basic Test​

  1. Open the Playground.
  2. Enter a sample prompt that should trigger the policy you just activated (e.g., a message containing PII if you activated a Privacy policy).
  3. Review the detection result: confirm that the policy fires, the correct confidence level is reported, and the expected action is applied.
  4. Test a benign prompt to verify it passes through without being flagged.
  5. Adjust the confidence level or action settings if the results are not as expected, and re-test.
  6. To check a whole set of cases at once, attach a CSV of prompts instead of typing them one by one — see Testing a batch of prompts under Playground.

Step 5 — Run at Scale Using the SDK or API​

To use the WonderFence SDK or API, generate an API key:

  1. Click on the Settings icon at the bottom-left menu.
  2. Click on Alice API Keys.
  3. Click on the Add Key button and enter the key name and description.
  4. Copy the generated API key and paste it into your code.

Getting Help​

  • Alice Online Chat — Click the chat icon to chat with an Alice representative.
  • Alice WonderSuite User Guides — This guide and the Alice Integration and API Guide, accessed via the API DOCUMENTATION link in the bottom-left corner of the page.