Abstract
Large language model agents increasingly act in deployment environments where failures are contextual, user-specific, and costly. In such settings, a \emph{static general-purpose guardrail is often insufficient}: whether an action should be allowed may depend on local privacy norms, organizational rules, or evolving user expectations that are difficult to enumerate fully in advance. We study \emph{lifelong deployment-time guardrail adaptation}, where a fixed base guardrail improves over time from sparse, noisy user-reported failures without repeated fine-tuning. We propose a conservative policy induction framework organized as an online--offline loop. Online, the deployed guardrail uses structured policy memory to guide runtime decisions. Offline, newly accumulated reports are converted into reusable policy items and folded back into memory through periodic refresh. The method combines three ingredients: \emph{broad policy abstraction} for sparse failure generalization, \emph{conflict-aware local policies} for mixed-label regions where broad reuse becomes too coarse, and \emph{confidence-gated reuse} based on conservative posterior lower bounds so that weakly supported memory does not influence inference too early. Across PrivacyLens+, ConFaide+, and AgentHarm, the resulting system consistently improves over a lightweight base guardrail and strong memory-based baselines in sparse-feedback regimes, remains robust to noisy feedback, traces a better cost--performance frontier than scaling the base model alone, and jointly reduces over-refusal and over-acceptance without an explicit balance knob.