Audit finding M-19: the employee-facing assistant had no guardrail
despite access to QBO, payments, WO/PO, and HR/SA8000 data.
Adds prompt-attack (HIGH input), content filters, and masking of
credential/financial identifiers (SSN, cards, bank numbers, keys).
Names/emails/phones deliberately unmasked - vendor contact lookup is
the bot's core function. MISCONDUCT output at MEDIUM so SA8000
misconduct-reporting questions are not suppressed.
Cross-reviewed (1 BLOCK fixed: ApplyGuardrail now covers version-
suffixed ARNs; explicit guardrail->version->agent dependencies added).
Alias description bump forces a new agent version (v10) so the live
alias snapshots the guardrail config.