A guardrail is an enforceable check that can allow, deny, or rewrite a model hop before it lands. Internals: intercept, evaluate facts, fail closed. Java samples for input and tool rails.