GuardrailReviewMiddleware
Runs guardrails as GuardrailMiddleware does, but a refusal asks a reviewer instead of blocking: the turn suspends with a GuardrailReview, and the GuardrailVerdict it is answered with lets the text through, replaces it, or blocks the run as GuardrailMiddleware would have. Text the guardrails accept passes without a question, and a guardrail that transforms (Fix) still applies.
While an input review waits, nothing of the turn is stored; while an output review waits, the answer is stored but the turn has no outcome yet. A verdict is used only for the text and phase it was asked about, whatever the refusal's reason, and the guardrails do not run on that text again once it is given, so a judge whose reason varies is asked once; if the hook runs again on different text, the guardrails run on it and the reviewer may be asked again.
Attributes
- Graph
-
- Supertypes
Members list
Value members
Concrete methods
Sees the run's final answer: returns it, possibly changed, or Left to fail the run.
Sees the run's final answer: returns it, possibly changed, or Left to fail the run.
Attributes
- Definition Classes
Sees the run's input before anything else runs: returns it, possibly changed, or Left to fail the run.
Sees the run's input before anything else runs: returns it, possibly changed, or Left to fail the run.
Attributes
- Definition Classes
Inherited methods
This middleware's question and its answer, when its hook runs again after a resume; None before.
This middleware's question and its answer, when its hook runs again after a resume; None before.
Attributes
- Inherited from:
- Asking
Suspends the run with question; return it as the result of beforeAgent, afterAgent or wrapModelCall. A question that does not encode is that Left instead.
Suspends the run with question; return it as the result of beforeAgent, afterAgent or wrapModelCall. A question that does not encode is that Left instead.
Attributes
- Inherited from:
- Asking
Suspends the tool call with question; return it as the result of wrapToolCall.
Suspends the tool call with question; return it as the result of wrapToolCall.
Attributes
- Inherited from:
- Asking
Middleware this one must run inside of (be wrapped by); each must be registered in the same stack.
Middleware this one must run inside of (be wrapped by); each must be registered in the same stack.
Attributes
- Inherited from:
- AgentMiddleware
Middleware this one must run outside of (wrap); each must be registered in the same stack.
Middleware this one must run outside of (wrap); each must be registered in the same stack.
Attributes
- Inherited from:
- AgentMiddleware
Tools this middleware contributes; they join the loop's tool set and are validated like any other.
Tools this middleware contributes; they join the loop's tool set and are validated like any other.
Attributes
- Inherited from:
- AgentMiddleware
Wraps one model call. A wrapper may rewrite the request (inject a note, filter tools), call next more than once (retry, fallback), transform its result, or return Left, which fails the run. Only an AgentMiddleware.Asking wrapper suspends, by asking its question.
Wraps one model call. A wrapper may rewrite the request (inject a note, filter tools), call next more than once (retry, fallback), transform its result, or return Left, which fails the run. Only an AgentMiddleware.Asking wrapper suspends, by asking its question.
Filtering ModelRequest.tools shapes what the model is offered and is not a permission control: a tool the model calls anyway still runs through wrapToolCall, where denial belongs.
Attributes
- Inherited from:
- AgentMiddleware
Wraps one tool call, after its arguments were validated. A wrapper denies with ToolOutcome.Error("Denied: ..."), asks for approval with NeedsApproval(reason) (unless context.approved), fails the run with Fatal, and short-circuits by not calling next. It may call next more than once (retry) and transform the outcome next returns.
Wraps one tool call, after its arguments were validated. A wrapper denies with ToolOutcome.Error("Denied: ..."), asks for approval with NeedsApproval(reason) (unless context.approved), fails the run with Fatal, and short-circuits by not calling next. It may call next more than once (retry) and transform the outcome next returns.
Attributes
- Inherited from:
- AgentMiddleware
The state keys this middleware's wrapToolCall may add to a Success update.
The state keys this middleware's wrapToolCall may add to a Success update.
Attributes
- Inherited from:
- AgentMiddleware
Concrete fields
This middleware's identifier, unique in its stack; must match [a-zA-Z0-9_-]{1,64}.
This middleware's identifier, unique in its stack; must match [a-zA-Z0-9_-]{1,64}.