// Engineering Log
n8n: Part 6 — Guardrails Node: Protecting LLM Workflows
Published on 2026-09-22
// Fast route
This article belongs to the topic Security and protection.
n8n workflows using language models carry two types of risks. On the input side, a user can send personal data, an API key, or an attempt to “jailbreak” the model’s instructions. On the output side the model can produce an inappropriate response, someone else’s link, or leak something that was included in its context. Previously these checks were assembled manually from IF nodes, regular expressions, and additional model calls. The Guardrails node consolidates them in one place.
Two operations
According to n8n documentation the node has two operations:
- Check Text for Violations — checks the text against a selected set of rules. If at least one rule is violated, the item goes to the Fail branch; otherwise — to Pass.
- Sanitize Text — does not block the text, but finds violations and replaces them with placeholders, for example replacing an email address with a label.
Typically the node is placed twice: before calling the model (to check or sanitize input) and after it (to check the response before sending it to the user or another system).
Types of checks
| Check | What it does | Requires model |
|---|---|---|
| Keywords | searches for specified banned words | no |
| Jailbreak | detects attempts to circumvent the model’s instructions and restrictions | yes |
| NSFW | flags disallowed content | yes |
| PII | finds personal data | no |
| Secret Keys | finds API keys and credentials | no |
| Topical Alignment | checks that the text stays on a given topic | yes |
| URLs | blocks links except domains from an allowlist | no |
| Custom | custom check using the model with your prompt | yes |
| Custom Regex | custom regular expression pattern | no |
Checks that are performed by the model (Jailbreak, NSFW, Topical Alignment, Custom) require a connected chat-model node and have a threshold from 0.0 to 1.0. The lower the threshold, the stricter the check and the more false positives.
Example: support assistant
Task: customer messages arrive via a webhook, the model prepares a reply, the reply goes to the customer.
- Webhook receives the message.
- Guardrails, Sanitize Text with PII and Secret Keys checks — phone numbers, email addresses and accidentally included keys are replaced with placeholders before the text reaches the model and the execution logs.
- Guardrails, Check Text for Violations with a Jailbreak check — attempts to override instructions go to the Fail branch, where the workflow responds with a standard phrase and logs the event.
- AI Agent or model node prepares the response.
- Guardrails, Check Text for Violations on the response: Topical Alignment (“only questions about the product and orders”) and URLs with an allowlist of your domains.
- The Pass branch sends the reply to the customer; the Fail branch escalates the request to an operator.
What to consider
- Model-based checks cost money and time. Each of them is an additional model call. For a flow handling thousands of messages per day this is a noticeable expense and a response delay. Put cheap checks (Keywords, PII, Secret Keys, URLs, Custom Regex) first.
- Sanitization does not remove legal obligations. If personal data already arrived in the webhook, it passed through your n8n server and may have been saved in the execution history. Retention periods for history are configured separately — see the second part of the series.
- A cloud model means data transmission. For Russian companies, transferring personal data to an overseas model provider is a separate legal issue; sanitization before the call reduces the risk but does not fully resolve it.
- Thresholds are tuned on real data. Run a set of real requests through the workflow and see how many legitimate messages are filtered out.
Common mistakes
- Having only an output check and sending uncleaned input to the model.
- Making the Fail branch a dead end: the user doesn’t receive a reply and the operator is unaware of the request.
- Using the same model and the same prompt for checks as for the reply: the same vulnerability bypasses both.
- Not reviewing the execution history: without it it’s unclear which rules are producing false positives.
Guardrails does not make a language-model workflow safe by itself, but replaces dozens of homemade checks with a single clear node that is easy to maintain.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Security and protection
SSL, hardening, access control, service protection, and secure configurations.
Typical tasks behind this topic
- Set up SSL, certificates, and secure connections
- Restrict access and close unnecessary entry points
- Harden server and service configuration
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
As always, prompt and high-quality! I turn to Mikhail for server issues.
As always, prompt and high-quality! For server-related issues, I turn to Mikhail.
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related