> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opal.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up Paladin on self-hosted Opal

> Turn on Paladin in a self-hosted Opal deployment: choose an inference provider, create the agent, run it on every request in monitor mode, and go live when you're ready.

## Overview

Paladin is not a separate service. It runs inside the Opal backend you already deploy, as a step in the access-request review flow. So turning Paladin on in a self-hosted install is a configuration task, not a new deployment: you pick an inference provider, create the agent, and turn on Global Paladin to see its recommendations on every request.

This guide assumes you already run [self-hosted Opal](/docs/self-host-overview). If you don't, set that up first.

<Note>
  Paladin needs outbound access to a Claude model, either Anthropic's API or Amazon Bedrock. A fully air-gapped install cannot reach either endpoint, so Paladin is not available without egress to one of them. See [Choose an inference provider](#step-1-choose-an-inference-provider).
</Note>

## Prerequisites

* A running self-hosted Opal install.
* Admin access to Opal.
* An inference provider: either an Anthropic API key, or an AWS account with Amazon Bedrock and the Claude models enabled.

## Step 1: Choose an inference provider

Paladin runs on Claude, through your own model account. You connect the account in Opal itself, so there's nothing to change in your deployment. Two providers are supported today.

<Tabs>
  <Tab title="Anthropic API (recommended)">
    Inference runs on Anthropic's hosted API, on your own Anthropic account.

    <Steps>
      <Step title="Create an API key">
        On the [Claude platform](https://platform.claude.com/settings/keys), create an API key. Use a service account key scoped to a single workspace, not an Admin API key or a personal key. A personal key stops working when the person who created it leaves your organization. A dedicated workspace for Opal lets you set its own spend and rate limits.
      </Step>

      <Step title="Connect Anthropic API in Opal">
        Connect **Anthropic API** as an integration and paste the key. Opal checks the key with Anthropic when you save it, and stores it encrypted.

        <Frame caption="Paste your Anthropic API key when you connect the Anthropic API integration.">
          <img src="https://mintcdn.com/opalsecurity/PfcD7_PQsnIjFDg6/images/docs/paladin-anthropic-api-key.png?fit=max&auto=format&n=PfcD7_PQsnIjFDg6&q=85&s=35808913f9d780056e32234f4c602b1f" alt="The Link Anthropic API dialog, with a field for the Anthropic API key and a Create button." width="972" height="581" data-path="images/docs/paladin-anthropic-api-key.png" />
        </Frame>
      </Step>

      <Step title="Select it as your provider">
        Under **Settings → AI Features**, select **Anthropic - Your account**.

        <Frame caption="Choose Anthropic - Your account as the LLM provider.">
          <img src="https://mintcdn.com/opalsecurity/PfcD7_PQsnIjFDg6/images/docs/paladin-ai-provider-options.png?fit=max&auto=format&n=PfcD7_PQsnIjFDg6&q=85&s=12bcbce780ef79532dfbcfe1f0dedf69" alt="The LLM Provider dropdown in AI Features settings, listing Anthropic - Opal managed, Anthropic - Your account, and Amazon Bedrock - Your account." width="1464" height="382" data-path="images/docs/paladin-ai-provider-options.png" />
        </Frame>
      </Step>
    </Steps>

    This path requires outbound HTTPS from the Opal backend to `api.anthropic.com`.
  </Tab>

  <Tab title="Amazon Bedrock">
    Inference stays inside your own AWS account.

    <Steps>
      <Step title="Enable Claude in Bedrock">
        In your AWS account, make sure Amazon Bedrock and the Claude models are enabled.
      </Step>

      <Step title="Connect Amazon Bedrock in Opal">
        Connect **Amazon Bedrock** as an integration and paste a long-lived Bedrock API key generated in your AWS account. Opal stores the key encrypted.

        <Frame caption="Paste a Bedrock API key when you connect the Amazon Bedrock integration.">
          <img src="https://mintcdn.com/opalsecurity/PfcD7_PQsnIjFDg6/images/docs/paladin-bedrock-token.png?fit=max&auto=format&n=PfcD7_PQsnIjFDg6&q=85&s=bffb96358dbc33a98cbc63015b61af59" alt="The Link Bedrock dialog, with a field for the Bedrock token and a Create button." width="972" height="503" data-path="images/docs/paladin-bedrock-token.png" />
        </Frame>
      </Step>

      <Step title="Select it as your provider">
        Under **Settings → AI Features**, select **Amazon Bedrock - Your account** and choose the AWS region. Bedrock uses cross-region inference. The default region is `us-west-2`.

        <Frame caption="Choose Amazon Bedrock - Your account, then set the Bedrock region.">
          <img src="https://mintcdn.com/opalsecurity/PfcD7_PQsnIjFDg6/images/docs/paladin-bedrock-provider.png?fit=max&auto=format&n=PfcD7_PQsnIjFDg6&q=85&s=705d84d75919e2873484b5d969903aed" alt="The LLM Provider setting set to Amazon Bedrock - Your account, with the Bedrock region field below it." width="1464" height="320" data-path="images/docs/paladin-bedrock-provider.png" />
        </Frame>
      </Step>
    </Steps>

    This path requires that the Opal backend can reach the Bedrock runtime endpoint in your chosen region.
  </Tab>
</Tabs>

Pick the provider that matches your isolation requirements: the Anthropic API is the simplest, while Bedrock keeps inference within your AWS boundary. Either way, usage, billing, and data retention fall under your own agreement with the provider.

## Step 2: Create a Paladin agent

Once a provider is in place, create the agent in the app:

<Steps>
  <Step title="Open Settings → AI Features">
    Confirm AI features are enabled for your organization and that the provider you configured in Step 1 is selected.
  </Step>

  <Step title="Create the agent">
    Follow [Create a Paladin agent](/docs/paladin/overview#create-a-paladin-agent): name it, assign an owner, leave **Monitor mode** on, and enable the connectors it should read from.

    <Frame caption="Name the agent, pick an owner, and choose its mode and connectors.">
      <img src="https://mintcdn.com/opalsecurity/PfcD7_PQsnIjFDg6/images/docs/paladin-create-agent-form.png?fit=max&auto=format&n=PfcD7_PQsnIjFDg6&q=85&s=4982911d192e25a6dfe29338531339c8" alt="The New Paladin agent dialog, with Name and Owner fields, Monitor mode and Show to admins only toggles, and connector toggles for Jira, Linear, Notion, and PagerDuty." width="1224" height="1020" data-path="images/docs/paladin-create-agent-form.png" />
    </Frame>
  </Step>
</Steps>

## Step 3: Turn on Global Paladin

Start with Global Paladin rather than adding the agent to specific approval flows. It runs your agent in monitor mode on every access request, so Paladin records a recommendation on each one while your reviewers still approve or deny. You don't have to change any approval flows.

Under **Settings → AI Features**, turn on **Global Paladin** and select the agent you created. Global Paladin needs an agent in monitor mode. If you don't have one yet, Opal prompts you to create it. See [Global Paladin](/docs/paladin/access-request#global-paladin).

<Frame caption="Turn on Global Paladin and select a monitor-mode agent.">
  <img src="https://mintcdn.com/opalsecurity/PfcD7_PQsnIjFDg6/images/docs/paladin-global-paladin.png?fit=max&auto=format&n=PfcD7_PQsnIjFDg6&q=85&s=7f9c769e675f77826b6a6a101e6018eb" alt="The Global Paladin setting in AI Features, switched on, with an agent picker listing the Paladin agent." width="1464" height="338" data-path="images/docs/paladin-global-paladin.png" />
</Frame>

## Step 4: Verify, then go live

Submit a test request and confirm Paladin's recommendation appears on it. Then watch its recommendations on real requests until you trust them.

When you're ready for Paladin to act, add an agent with monitor mode off as a reviewer on the approval flows you choose. See [Configure Paladin as a reviewer](/docs/paladin/access-request#configure-paladin-as-a-reviewer) for sole-reviewer versus advisory setups, and [Monitor mode](/docs/paladin/access-request#monitor-mode) for how to turn it off.

## Data handling

Paladin's decision records are stored in your own Opal database alongside the rest of your tenant's data. Its short-term working memory is held in Redis and expires within 24 hours. Prompts go only to the model provider you connected, and their retention follows your agreement with that provider. For a full data-flow and subprocessor breakdown for a security or compliance review, contact your Opal representative.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.