Because prompt tuning is a suggestion. A model asked nicely not to discuss refunds will discuss refunds when a customer is persistent enough, and the failure is public.
Guardrails define what the AI agent may say, what it must escalate, and what data it may read.
Guardrails are enforced outside the model: topic blocks, a mandatory citation rule, a confidence floor, and hard handover triggers. An answer that cannot cite a source is not sent, whatever the model produced.
A customer asks whether they will be charged for an overage. The agent has an article on the pricing model but nothing about their specific case, so the answer is blocked and handed to a person.
They will not catch a wrong article. If your knowledge base states something incorrect, a cited answer will be confidently wrong — which is why citation matters, since it points at what to fix.
Topics the agent may not address, data it may not read, the citation requirement, and the conditions that force handover.
Yes, any number, and they are enforced rather than suggested.
Yes, with its sources, reviewable at any time.
Yes — premium accounts can go straight to a person.
Fourteen days, every module, no card. Or half an hour with someone who will run it on your own records and tell you where it does not help.