Skip to main content

Post-Execution Governance

TealTiger v1.4 extends governance to LLM outputs. Pre-execution scanning blocks dangerous inputs. Post-execution scanning blocks sensitive outputs. Together, they provide bi-directional defense.

The Problem

Pre-execution governance catches threats going into the model. But models can generate sensitive content:
  • Secrets in training data: Models sometimes output API keys, passwords, or connection strings they were trained on
  • PII in completions: Names, email addresses, phone numbers, SSNs generated in responses
  • Harmful content: The model produces content that violates your organization’s policies
  • Data exfiltration via output: A compromised prompt causes the model to leak context window contents
Pre-execution scanning alone can’t catch these — the dangerous content doesn’t exist until after the model generates it.

How It Works

Bi-directional pre/post scanning The post-scan executes after the provider response is received but before it’s returned to the caller. In ENFORCE mode, blocked content never reaches your application code.

Configuration

Independent Configuration

pre and post are fully independent. You can configure:
  • Both: Full bi-directional scanning
  • Only pre: Traditional input-only scanning (v1.3 behavior)
  • Only post: Output-only scanning (useful when you trust inputs but not model outputs)
  • Neither: No guardrails (governance via policy only)

Enforcement Modes

Post-execution guardrails support the same enforcement modes as pre-execution:
You can also set different modes for pre and post:

Audit Trail

Every scan produces an audit event with a phase field distinguishing pre from post:
The audit trail makes it clear whether a governance event was triggered by input content or output content.

Use Cases

Secret Leakage in Responses

Models trained on code sometimes output API keys or credentials from their training data:

PII in Model Outputs

Customer service agents that generate responses containing user PII:

Harmful Content Generation

Models that produce content violating organizational policies:

Context Window Exfiltration

A compromised prompt causes the model to dump its context (including other users’ data):

Multi-Stage Integration

Post-execution governance integrates with the multi-stage defense pipeline. The depth setting applies to post-scan as well:
Both pre and post scans run through Stage 1 (pattern) and Stage 2 (structural) when depth: "standard" is configured.

Backward Compatibility

If no post guardrails are configured, TealGuard behaves identically to v1.3:
The guardrails configuration is fully backward compatible. Existing v1.3 configurations continue to work without modification.

Performance Impact

Post-execution scanning adds latency after the LLM responds but before the response reaches your code: Since the LLM response typically takes 500ms–5s, the post-scan overhead is negligible relative to total request time.