Skip to main content

Observe vs Enforce Mode

AgenticGuard has two operating modes. Understanding when to use each is key to a safe rollout.

Observe mode​

In observe mode, all calls are allowed regardless of policy. AgenticGuard logs every call and records which rules would have matched, but does not block anything.

Use observe mode to:

  • Understand what tools your agent actually calls in production
  • Identify which calls need policies before you write rules
  • Audit an existing agent without risk of breakage
gate = AgenticGuard(api_key="ag_xxx", mode="observe")

Enforce mode​

In enforce mode, policy-matching calls are blocked. A PolicyViolationError is raised so your agent can handle it gracefully.

Use enforce mode in production once you have:

  • Reviewed the observe-mode audit log
  • Written policies that reflect your intent
  • Tested that legitimate calls are not accidentally blocked
gate = AgenticGuard(api_key="ag_xxx", mode="enforce")
1. Start in observe mode
↓
2. Review audit log — see what your agent calls
↓
3. Write policies based on observed behavior
↓
4. Test policies in observe mode (watch for would-deny events)
↓
5. Switch to enforce mode
↓
6. Monitor audit log for unexpected denials

Side-by-side comparison​

ObserveEnforce
Blocks policy violations✓
Logs all calls✓✓
Raises PolicyViolationError✓
Safe to deploy without policies✓✓ (all allowed by default)
Recommended for productionMonitoring only✓

The proxy URL is always enforce​

The proxy URL integration always operates in enforce mode — it is a server-side proxy and has no "observe" concept. If you want to start in observe mode, use the SDK.

Mixing modes​

You can run multiple agents with different modes — for example, one agent in observe mode for a new workflow, while another is in enforce mode for a stable one.