Skip to main content
Authentication identifies the caller; authorization decides which resources and effects that caller may use. Model instructions and output filters do not replace either boundary.

Host an authenticated API

Use the complete authenticated transport example for verified identity and resource authorization. Its host callbacks must atomically bind new sessions and deny unknown or foreign resources. Configure JWT/RBAC or API keys at that boundary. A provider API key grants model access; it is not an application user identity. See tenant isolation before sharing storage or clients.

Validate input and output

This complete example bounds text input and rejects an empty final answer. It uses the v4 validate/pass contract. Install @agentium/core@4.0.0, openai, and a TypeScript runner; set OPENAI_API_KEY.
An output guardrail accepts or rejects the result; there is no outputAction: "sanitize" option. Perform deliberate output transformation in application code where the presentation contract needs it. Guardrails are not a general SQL-injection defense; parameterize database queries and authorize each operation.

Scrub selected data

The guard uses configured detectors; it is not proof that arbitrary text contains no sensitive data. PII guidance explains hooks and rehydration. Rehydrating before returning an answer restores the original values.

Approve effects

Use the complete approval tutorial to require a human decision for a tool. The approval request should show the exact arguments that will execute. Timeout should settle the request according to your configured policy. An approval does not undo an effect or make replay safe. For a harness, configure execution policy and approval together with explicit tool grants. For outbound calls, OutboundCallService rechecks host authorization for create, read, hangup, reconciliation, and event updates.

Isolate code execution

Choose local, E2B, or Daytona based on the trust of the program and ownership of its workspace. unix-local is trusted host execution. A tool that returns the text “Executed” has not run or isolated code; use an actual backend and inspect its result. See sandbox controls, path safety, and service recovery for their specific enforcement boundaries.