Developer guides

Put the check before the action

These guides show where an advisory check belongs and which integration point refuses a non-permitted tool call.

Framework integrations

LangGraph pre-action check

Route every non-permit result to a refusal node before the execution node.

OpenAI Agents SDK pre-action check

Wrap a function tool so only an exact permit calls the underlying operation.

Claude Agent SDK pre-action check

Use a PreToolUse callback that denies every non-permit result.

Write and validate an agent mandate

Start from a template, validate the structured boundary, and test representative actions.

Shared rule

The check returns permit, deny, or escalate with the governing clause and a signed receipt. It is advisory. Your graph route, wrapper, or integration is what refuses the action. Treat every error as deny.

Try the check · Verify signed receipts · OpenAPI document · Agent-facing summary