Glossary

    Guardrail

    Compliance & Governance

    A Guardrail is a security boundary that prevents or detects actions that violate your organization's security policies. Unlike permissions that grant access, guardrails restrict what is possible - even for administrators.

    Guardrail Types

    • Preventive: SCPs that block actions before they happen (e.g., deny launching instances without encryption)
    • Detective: AWS Config rules that flag non-compliant resources after the fact
    • Proactive: CloudFormation hooks or Service Catalog constraints that validate before deployment

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.