Skip to main content

Overview

Paladin is not a separate service. It runs inside the Opal backend you already deploy, as a step in the access-request review flow. So turning Paladin on in a self-hosted install is a configuration task, not a new deployment: you pick an inference provider, create the agent, and turn on Global Paladin to see its recommendations on every request. This guide assumes you already run self-hosted Opal. If you don’t, set that up first.
Paladin needs outbound access to a Claude model, either Anthropic’s API or Amazon Bedrock. A fully air-gapped install cannot reach either endpoint, so Paladin is not available without egress to one of them. See Choose an inference provider.

Prerequisites

  • A running self-hosted Opal install.
  • Admin access to Opal.
  • An inference provider: either an Anthropic API key, or an AWS account with Amazon Bedrock and the Claude models enabled.

Step 1: Choose an inference provider

Paladin runs on Claude, through your own model account. You connect the account in Opal itself, so there’s nothing to change in your deployment. Two providers are supported today.
Pick the provider that matches your isolation requirements: the Anthropic API is the simplest, while Bedrock keeps inference within your AWS boundary. Either way, usage, billing, and data retention fall under your own agreement with the provider.

Step 2: Create a Paladin agent

Once a provider is in place, create the agent in the app:
1

Open Settings → AI Features

Confirm AI features are enabled for your organization and that the provider you configured in Step 1 is selected.
2

Create the agent

Follow Create a Paladin agent: name it, assign an owner, leave Monitor mode on, and enable the connectors it should read from.
The New Paladin agent dialog, with Name and Owner fields, Monitor mode and Show to admins only toggles, and connector toggles for Jira, Linear, Notion, and PagerDuty.

Name the agent, pick an owner, and choose its mode and connectors.

Step 3: Turn on Global Paladin

Start with Global Paladin rather than adding the agent to specific approval flows. It runs your agent in monitor mode on every access request, so Paladin records a recommendation on each one while your reviewers still approve or deny. You don’t have to change any approval flows. Under Settings → AI Features, turn on Global Paladin and select the agent you created. Global Paladin needs an agent in monitor mode. If you don’t have one yet, Opal prompts you to create it. See Global Paladin.
The Global Paladin setting in AI Features, switched on, with an agent picker listing the Paladin agent.

Turn on Global Paladin and select a monitor-mode agent.

Step 4: Verify, then go live

Submit a test request and confirm Paladin’s recommendation appears on it. Then watch its recommendations on real requests until you trust them. When you’re ready for Paladin to act, add an agent with monitor mode off as a reviewer on the approval flows you choose. See Configure Paladin as a reviewer for sole-reviewer versus advisory setups, and Monitor mode for how to turn it off.

Data handling

Paladin’s decision records are stored in your own Opal database alongside the rest of your tenant’s data. Its short-term working memory is held in Redis and expires within 24 hours. Prompts go only to the model provider you connected, and their retention follows your agreement with that provider. For a full data-flow and subprocessor breakdown for a security or compliance review, contact your Opal representative.
Last modified on October 9, 2026