GuardrailReviewMiddleware

org.llm4s.agent.graph.middleware.GuardrailReviewMiddleware

Runs guardrails as GuardrailMiddleware does, but a refusal asks a reviewer instead of blocking: the turn suspends with a GuardrailReview, and the GuardrailVerdict it is answered with lets the text through, replaces it, or blocks the run as GuardrailMiddleware would have. Text the guardrails accept passes without a question, and a guardrail that transforms (Fix) still applies.

While an input review waits, nothing of the turn is stored; while an output review waits, the answer is stored but the turn has no outcome yet. A verdict is used only for the text and phase it was asked about, whatever the refusal's reason, and the guardrails do not run on that text again once it is given, so a judge whose reason varies is asked once; if the hook runs again on different text, the guardrails run on it and the reviewer may be asked again.

Attributes

Graph
Supertypes
class Object
trait Matchable
class Any

Members list

Value members

Concrete methods

override def afterAgent(answer: String, context: RunContext): Result[String]

Sees the run's final answer: returns it, possibly changed, or Left to fail the run.

Sees the run's final answer: returns it, possibly changed, or Left to fail the run.

Attributes

Definition Classes
override def beforeAgent(text: String, context: RunContext): Result[String]

Sees the run's input before anything else runs: returns it, possibly changed, or Left to fail the run.

Sees the run's input before anything else runs: returns it, possibly changed, or Left to fail the run.

Attributes

Definition Classes

Inherited methods

final protected def answered(context: ToolContext): Option[Resumed[GuardrailReview, GuardrailVerdict]]

answered for a tool call's context.

answered for a tool call's context.

Attributes

Inherited from:
Asking
final protected def answered(context: RunContext): Option[Resumed[GuardrailReview, GuardrailVerdict]]

This middleware's question and its answer, when its hook runs again after a resume; None before.

This middleware's question and its answer, when its hook runs again after a resume; None before.

Attributes

Inherited from:
Asking
final protected def ask(question: GuardrailReview): Result[Nothing]

Suspends the run with question; return it as the result of beforeAgent, afterAgent or wrapModelCall. A question that does not encode is that Left instead.

Suspends the run with question; return it as the result of beforeAgent, afterAgent or wrapModelCall. A question that does not encode is that Left instead.

Attributes

Inherited from:
Asking
final protected def askAbout(question: GuardrailReview): ToolOutcome

Suspends the tool call with question; return it as the result of wrapToolCall.

Suspends the tool call with question; return it as the result of wrapToolCall.

Attributes

Inherited from:
Asking

Middleware this one must run inside of (be wrapped by); each must be registered in the same stack.

Middleware this one must run inside of (be wrapped by); each must be registered in the same stack.

Attributes

Inherited from:
AgentMiddleware

Middleware this one must run outside of (wrap); each must be registered in the same stack.

Middleware this one must run outside of (wrap); each must be registered in the same stack.

Attributes

Inherited from:
AgentMiddleware
def tools: Vector[AgentTool[_]]

Tools this middleware contributes; they join the loop's tool set and are validated like any other.

Tools this middleware contributes; they join the loop's tool set and are validated like any other.

Attributes

Inherited from:
AgentMiddleware

Wraps one model call. A wrapper may rewrite the request (inject a note, filter tools), call next more than once (retry, fallback), transform its result, or return Left, which fails the run. Only an AgentMiddleware.Asking wrapper suspends, by asking its question.

Wraps one model call. A wrapper may rewrite the request (inject a note, filter tools), call next more than once (retry, fallback), transform its result, or return Left, which fails the run. Only an AgentMiddleware.Asking wrapper suspends, by asking its question.

Filtering ModelRequest.tools shapes what the model is offered and is not a permission control: a tool the model calls anyway still runs through wrapToolCall, where denial belongs.

Attributes

Inherited from:
AgentMiddleware
def wrapToolCall(request: ToolCallRequest, context: ToolContext)(next: () => ToolOutcome): ToolOutcome

Wraps one tool call, after its arguments were validated. A wrapper denies with ToolOutcome.Error("Denied: ..."), asks for approval with NeedsApproval(reason) (unless context.approved), fails the run with Fatal, and short-circuits by not calling next. It may call next more than once (retry) and transform the outcome next returns.

Wraps one tool call, after its arguments were validated. A wrapper denies with ToolOutcome.Error("Denied: ..."), asks for approval with NeedsApproval(reason) (unless context.approved), fails the run with Fatal, and short-circuits by not calling next. It may call next more than once (retry) and transform the outcome next returns.

Attributes

Inherited from:
AgentMiddleware
def writes: Set[StateKey[_, _]]

The state keys this middleware's wrapToolCall may add to a Success update.

The state keys this middleware's wrapToolCall may add to a Success update.

Attributes

Inherited from:
AgentMiddleware

Concrete fields

This middleware's identifier, unique in its stack; must match [a-zA-Z0-9_-]{1,64}.

This middleware's identifier, unique in its stack; must match [a-zA-Z0-9_-]{1,64}.

Attributes