Developer guides
Put the check before the action
These guides show where an advisory check belongs and which integration point refuses a non-permitted tool call.
Framework integrations
LangGraph pre-action check
Route every non-permit result to a refusal node before the execution node.
OpenAI Agents SDK pre-action check
Wrap a function tool so only an exact permit calls the underlying operation.
Claude Agent SDK pre-action check
Use a PreToolUse callback that denies every non-permit result.
Write and validate an agent mandate
Start from a template, validate the structured boundary, and test representative actions.
Shared rule
The check returns permit, deny, or escalate with the governing clause and a signed receipt. It is advisory. Your graph route, wrapper, or integration is what refuses the action. Treat every error as deny.
Try the check · Verify signed receipts · OpenAPI document · Agent-facing summary