Incidents
Quard opens an incident for a run when a guard blocks a call, or when a guard finds something in content: the source scan, the AI detector or a signature flags or strips what a tool returned. Both count in observe mode too, where the guard only records what it would do. A run has at most one incident, opened at the first of these.
Content the AI detector could not check is flagged detector:unchecked, but that alone does not open an incident. Neither does masking data in a call’s arguments, an allow, a pass or an ask.
The incident page shows the path from where untrusted content came in to where the harm was done or stopped, a verdict, and a replay that tests the cause.
Quard finds the verdict and writes the AI explanation on its own, in the background. Replay runs only when you start it.
Until Quard opens its first incident, the list stays in place and reads No incidents yet.
Incident list

- Search. Find incidents by title, entry point, damage or agent.
- Category. Show one kind of cause. Each kind shows how many incidents it has.
- Replay. Show incidents by the state of their replay.
- An incident. Its title, category, entry point, damage, the agents involved, the state of its replay and how long ago it opened. Click the row to open it.
| Category | What went wrong |
|---|---|
| Bad input | Untrusted content steered the agent |
| Bad reasoning | The model made a harmful choice without being steered |
| Bad handoff | A message between agents sent wrong information, dropped a constraint, or was misread |
| Broken tool | A tool returned wrong data |
| Missing guard | No guard was in place to stop the harmful call |
When untrusted content passes from one agent to another, the incident stays Bad input and names the handoff that carried it. Bad handoff is for a message that brought a damaging value no untrusted content holds: it sent wrong information, or a correct message was misread. Quard does not store message text, so it never says a constraint was dropped.
Incident page

- Incident. What happened, when the incident opened and the status of its run. Open run opens the full run. The replay button starts replay.
- Path from entry point to damage. Every step from where untrusted content came in to the harmful call, read left to right. Entry point is where untrusted content came in. Handoff is where it passed to another agent. Turning point is the model call that decided to act on it. Damage is the harmful call. When no call was blocked, the damage is the first tool call whose content a guard flagged, and the entry point is that content, so the category is Bad input. With no flagged content either, when the run went over its step or cost limit, the damage is the model call that went over it. Each step shows its agent and origin.
- Replay results. Replay reruns the turning-point model call in rounds of 5 with the suspect content and 5 without it, up to 20 each. The line at the top says where the replay stands. Each round shows how many reruns were harmful on each side and the p value so far. The cost covers every model call made for this incident, up to a $5 cap. Setup names the model, the call that counts as harmful and the content left out. Table lists each round with its cost.
- Verdict. The category and the missing guard. observe only means the guard exists but only records. For a bad handoff, it also says what went wrong. Agent versions lists the version of each agent involved.
- AI explanation. A short explanation in plain words, written by an AI using your own OpenAI key. It only explains: the verdict comes from labels, value tracing and replay.
Right after an incident opens, Quard is still finding its verdict, and the page says so. A blocked call wins, so for flagged content or a run limit Quard waits for the run to end, for up to 5 minutes. If the damaging call’s events never reach Quard, it stops after 5 minutes and the page says the verdict could not be found.
Replay
Replay tests whether the suspect content caused the harm. It reruns the turning-point model call with the content and without it, and counts how often the model asks for the same harmful call. It never runs real tools: each rerun only reads which tool call the model asks for.
- Start it. Click the replay button at the top of the incident page. Replay then runs in rounds until the answer is clear or the cost cap is reached. The page updates while it runs.
- Cost cap. Every model call made for an incident counts toward a $5 cap, the AI explanation included. Replay stops before a round would pass it. The button then offers Continue with $5 more, which keeps the rounds so far.
- Button turned off. While replay runs, and once the answer is clear, the button is turned off. Hover it to see why.
- Your key. Replay and the AI explanation use the OpenAI key set on the worker as
OPENAI_API_KEY. Without it, there is no explanation, and replay fails and says so.
| Status | What it means |
|---|---|
| Not started | No one has started replay yet |
| Replaying | Replay is running |
| Confirmed | Harm is clearly more common with the suspect content than without it |
| Not confirmed | Even if every remaining rerun went the right way, the test could not pass |
| Could not reproduce | None of the first 10 reruns with the content was harmful |
| Cap reached | Replay stopped at the cost cap. Continue with $5 more goes on from there |
| Limited | Replay can’t run for this incident. The page says why |
| Failed | Replay hit an error, such as a missing key. Fix it, then start replay again |
Replay cannot show a cause that triggers harm only rarely, that the removed content was the only cause, or how a different model version would behave.
How replay rebuilds the call
Replay needs the turning-point request as your agent sent it. While the SDK uploads events to Quard, it records the request of each model call, redacted like every event.
- A request that continues an earlier response with
previous_response_idis rebuilt from the requests and answers recorded before it. - Masked values, such as IBANs and emails, are replaced with stand-ins in the same format, built from the stored hash. An IBAN stand-in has a valid checksum, and an email keeps its domain.
- The side without the suspect content keeps the tool call but replaces its result with
[Removed for replay]. - Hosted web search is left out of the rerun.
When replay is limited
Replay is limited, and does not run, when:
- The request was not recorded. Uploads were off, or the request was larger than 512 KiB. Agents that resend the whole history on every call can pass that size in long runs.
- Earlier history was not recorded. The request continues an earlier response that Quard has no request for, or uses a
conversation. - The suspect content is not a tool result in the turning-point request, such as text from the user or from a hosted web search. Content another agent passed on in a message is fine: replay leaves out that message.
A verdict with no suspect content, such as bad reasoning, has nothing to replay.
- There is no harmful call to test. A guard flagged the content and the agent did nothing harmful with it, or the run went over a run limit.