GuardRail: Organizational Behavior

GuardRail: Organizational Behavior

WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Welcome
Supported Applications & LLMs
Release Notes
August 18, 2026 WitnessAI Release
August 4, 2026 WitnessAI Release
July 21, 2026 WitnessAI Release
July 14, 2026 WitnessAI Release
July 9, 2026 WitnessAI Release
June 30, 2026 WitnessAI Hotfix
June 23, 2026 WitnessAI Release
June 16, 2026 WitnessAI Release
June 11, 2026 WitnessAI Release
June 4, 2026 WitnessAI Hotfix
June 2, 2026 WitnessAI Update
May 19, 2026 WitnessAI Update
April 30, 2026 WitnessAI Update
April 28, 2026 WitnessAI Update
April 23, 2026 WitnessAI Update
April 16, 2026 WitnessAI Update
April 14, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 7, 2026 WitnessAI Update
April 2, 2026 WitnessAI Update
March 31, 2026 WitnessAI Update
March 24, 2026 WitnessAI Update
March 19, 2026 WitnessAI Update
March 17, 2026 WitnessAI Update
March 12, 2026 WitnessAI Update
March 5, 2026 WitnessAI Update
February 26, 2026 WitnessAI Update
February 24, 2026 WitnessAI Update
February 10, 2026 WitnessAI Update
January 27, 2026 WitnessAI Update
January 20, 2026 WitnessAI Update
January 13, 2026 WitnessAI Update
December 18, 2025 WitnessAI Update
December 9, 2025 WitnessAI Update
November 25, 2025 WitnessAI Update
November 18, 2025 WitnessAI Update
November 11, 2025 WitnessAI Update
October 28, 2025 WitnessAI Update
October 23, 2025 WitnessAI Update
October 9, 2025 WitnessAI Update
October 2, 2025 WitnessAI Update
September 30, 2025: WitnessAI Update
September 23, 2025: WitnessAI Update
August 12, 2025: WitnessAI Update
July 31, 2025: WitnessAI Update
July 18, 2025: WitnessAI Update
April 11, 2025: WitnessAI Release v2.0
June 9, 2025: WitnessAI Update
June 23, 2025: WitnessAI Update
TOC Left Sidebar: not active
TOC Left Sidebar: ORIGINAL
User Guide
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
404
 

Organizational Behavior GuardRail

Organizational Behavior is WitnessAI’s modeled multi-prompt aware Guardrail. The purpose of this Guardrail is to examine an employee’s prompts and score various “meta” behaviors. For example, an employee that may wish to leave the company. When this Guardrail detects these activities, it provides the option to create an Alert in the Witness Console, or push an event to a supported SIEM tool.

Behavioral Alerts

Detection Criteria
If an employee engages with three or more of the defined behavioral queries within a short time frame (e.g., a week), it may indicate the potential for the described risk.

Burnout Disengagement

Intention
Detect signs of disengagement, low morale, or burnout in employees.
Detection Criteria
If an employee engages with three or more of these queries within a short time frame (e.g., a week), it may indicate potential burnout or disengagement from their role.

Potentially Departing Employee

Intention
Track signs of an employee seeking to reskill or transition to a different career path, either internally or externally.
Detection Criteria
Two or more prompts related to learning new skills or transitioning careers over a short period may indicate an intention to change job roles or industries.

Workplace Conflict

Intention
Track potential signs of internal conflict or dissatisfaction with colleagues or management.
Detection Criteria
If an employee asks three or more queries related to conflict resolution, workplace issues, or reporting problems in a short span, this might signal potential internal conflict or growing dissatisfaction.

External Opportunity Exploration (Side Projects or Freelance)

Intention
Detect whether an employee is exploring side projects, freelancing, or moonlighting opportunities.
Detection Criteria
If an employee interacts with two or more prompts about side projects or freelancing within a few days, it could indicate a divided focus or intention to pursue outside work.

Malicious Intent (Fraud or Insider Threats)

Intention
Detect malicious intentions, such as fraud, insider threats, or deliberate harm to the company.
Detection Criteria
One or more high-risk prompts related to fraudulent activities or deliberate harm could signal immediate danger or malicious insider activity.

Knowledge Hoarding


Intention
Identify when an employee is hoarding or monopolizing knowledge for leverage or improper reasons.

Detection Criteria
Two or more queries related to hiding or withholding information could signal knowledge hoarding or potential misuse of internal resources.

Violation of Company Policies

Intention
Identify potential behaviors indicating that an employee may be attempting to bypass or violate company policies.
 
Detection Criteria
If two or more of these types of prompts are detected within a certain timeframe, it could signal a potential intention to violate security or company policies.

Using Organizational Behavior Step-by-Step

This section covers details on the Organizational Behavior GuardRail, and how to add it to a Policy. Refer to the Policy Creation page for how to create Policies.

Add a Organizational Behavior GuardRail

WitnessAI policy editor showing how to add the Organizational Behavior (Beta) GuardRail. Numbered callouts show: (1) ‘Organizational Behavior (Beta)’ selected in left panel (orange highlight), (2) master toggle enabled (blue), (3) Enable Alerts section with individual toggles for: Burned Risk, Potentially Departing Employee, Workplace Conflict, Freelance/Side Work, Malicious Intent, Knowledge Hoarding, Violation of Company Policies. A warning note about 7-day detection window is shown.
After creating a Policy
  1. Click the Guard Rails tab in the policy editor.
  2. Select the Organizational Behavior GuardRail from the available options.
  3. Click the top slide button to enable the GuardRail.
  4. Click the slide buttons for each Alert you want to enble.
  5. Save the configuration.