Turn on Paladin in a self-hosted Opal deployment: choose an inference provider, create the agent, run it on every request in monitor mode, and go live when you’re ready.
Paladin is not a separate service. It runs inside the Opal backend you already deploy, as a step in the access-request review flow. So turning Paladin on in a self-hosted install is a configuration task, not a new deployment: you pick an inference provider, create the agent, and turn on Global Paladin to see its recommendations on every request.This guide assumes you already run self-hosted Opal. If you don’t, set that up first.
Paladin needs outbound access to a Claude model, either Anthropic’s API or Amazon Bedrock. A fully air-gapped install cannot reach either endpoint, so Paladin is not available without egress to one of them. See Choose an inference provider.
Paladin runs on Claude, through your own model account. You connect the account in Opal itself, so there’s nothing to change in your deployment. Two providers are supported today.
Anthropic API (recommended)
Amazon Bedrock
Inference runs on Anthropic’s hosted API, on your own Anthropic account.
1
Create an API key
On the Claude platform, create an API key. Use a service account key scoped to a single workspace, not an Admin API key or a personal key. A personal key stops working when the person who created it leaves your organization. A dedicated workspace for Opal lets you set its own spend and rate limits.
2
Connect Anthropic API in Opal
Connect Anthropic API as an integration and paste the key. Opal checks the key with Anthropic when you save it, and stores it encrypted.
Paste your Anthropic API key when you connect the Anthropic API integration.
3
Select it as your provider
Under Settings → AI Features, select Anthropic - Your account.
Choose Anthropic - Your account as the LLM provider.
This path requires outbound HTTPS from the Opal backend to api.anthropic.com.
Inference stays inside your own AWS account.
1
Enable Claude in Bedrock
In your AWS account, make sure Amazon Bedrock and the Claude models are enabled.
2
Connect Amazon Bedrock in Opal
Connect Amazon Bedrock as an integration and paste a long-lived Bedrock API key generated in your AWS account. Opal stores the key encrypted.
Paste a Bedrock API key when you connect the Amazon Bedrock integration.
3
Select it as your provider
Under Settings → AI Features, select Amazon Bedrock - Your account and choose the AWS region. Bedrock uses cross-region inference. The default region is us-west-2.
Choose Amazon Bedrock - Your account, then set the Bedrock region.
This path requires that the Opal backend can reach the Bedrock runtime endpoint in your chosen region.
Pick the provider that matches your isolation requirements: the Anthropic API is the simplest, while Bedrock keeps inference within your AWS boundary. Either way, usage, billing, and data retention fall under your own agreement with the provider.
Start with Global Paladin rather than adding the agent to specific approval flows. It runs your agent in monitor mode on every access request, so Paladin records a recommendation on each one while your reviewers still approve or deny. You don’t have to change any approval flows.Under Settings → AI Features, turn on Global Paladin and select the agent you created. Global Paladin needs an agent in monitor mode. If you don’t have one yet, Opal prompts you to create it. See Global Paladin.
Turn on Global Paladin and select a monitor-mode agent.
Submit a test request and confirm Paladin’s recommendation appears on it. Then watch its recommendations on real requests until you trust them.When you’re ready for Paladin to act, add an agent with monitor mode off as a reviewer on the approval flows you choose. See Configure Paladin as a reviewer for sole-reviewer versus advisory setups, and Monitor mode for how to turn it off.
Paladin’s decision records are stored in your own Opal database alongside the rest of your tenant’s data. Its short-term working memory is held in Redis and expires within 24 hours. Prompts go only to the model provider you connected, and their retention follows your agreement with that provider. For a full data-flow and subprocessor breakdown for a security or compliance review, contact your Opal representative.
Last modified on October 9, 2026
Was this page helpful?
Assistant
Responses are generated using AI and may contain mistakes.