Guardrail
A control that makes the unsafe action impossible or automatically corrected, rather than reviewing it before it happens.
Guardrails and gates both enforce a rule; they differ in where they sit relative to the developer's flow, and that difference decides both the friction and the reliability of the control.
A gate stops the flow and waits for a verdict — a review, an approval, a blocking scan. It is visible, it costs time on every change, and its enforcement is only as consistent as whoever or whatever is behind it. A guardrail changes the shape of the space instead: the network policy that denies by default, the account that cannot create public buckets, the deployment configuration a developer never writes because the platform generates it, the reconciliation loop that reverts non-compliant resources.
The advantage of guardrails is that safety costs nothing per change, so it does not compete with delivery pressure and does not degrade when the team is busy. The advantage of gates is that they handle judgement, which no guardrail can encode.
The practical design heuristic: guardrail everything expressible as a rule, gate only what requires a decision, and treat every recurring gate as a backlog item for a guardrail.