Skip to main content

SDK — Enforce Mode

Enforce mode blocks policy-violating tool calls before they execute. A PolicyViolationError is raised so your agent can handle it gracefully.

Basic usage​

from agentic_guard import AgenticGuard, PolicyViolationError

gate = AgenticGuard(
api_key="ag_xxxxxxxxxxxx",
base_url="https://api.agentic-guard.com",
mode="enforce",
)

try:
result = gate.call(
tool="github",
action="delete_repo",
tool_url="https://api.github.com/repos/myorg/myrepo",
method="DELETE",
reasoning="Cleaning up old repo",
task_id="cleanup_001",
)
except PolicyViolationError as e:
print(f"Blocked: {e.message}")
# Handle gracefully — log, notify, skip

PolicyViolationError​

class PolicyViolationError(Exception):
message: str # human-readable reason from the policy rule
tool: str # tool that was blocked
action: str # action that was blocked
rule_id: str # which rule matched (if named)

Example: require reasoning or block​

# Policy YAML
rules:
- tool: "*"
action: POST
require_reasoning: true
message: "POST calls require a reasoning header"

- tool: stripe
action: "*"
require_reasoning: true
message: "All Stripe calls must include reasoning"
# This raises PolicyViolationError
gate.call(tool="stripe", action="charge", tool_url="...", method="POST")

# This succeeds
gate.call(
tool="stripe",
action="charge",
tool_url="...",
method="POST",
reasoning="User confirmed purchase of plan Pro",
)

Building resilient agents​

def safe_tool_call(gate, **kwargs):
try:
return gate.call(**kwargs)
except PolicyViolationError as e:
# Log to your observability stack
logger.warning("Policy blocked: %s", e.message)
# Return a structured signal to the LLM
return {"error": "policy_violation", "message": e.message}

Pass the error back to the LLM so it can adapt its behavior — request user approval, skip the step, or choose an alternative tool.

Differences from observe mode​

ObserveEnforce
Allows all calls✓
Blocks on policy match✓
Logs every call✓✓
Raises exception✓
Good forMonitoringProduction safety