agent-governance (Python client)
Governance for AI agent tools — deny by default, L0–L4 guardrails, human approvals, full audit chain — via the agent-governance sidecar. Zero dependencies (stdlib only).
Install & adopt in three lines
# from this repository (works today, no PyPI needed):
pip install "git+https://github.com/NexusClawHQ/nexusclaw.git#subdirectory=governance/adapters/python"
# or from PyPI once published: pip install agentgovernance
from agent_governance import GovernanceClient
gov = GovernanceClient("http://127.0.0.1:7899")
update_customer = gov.wrap_tool(update_customer) # gated + audited
Every wrapped call now:
- asks the sidecar
POST /gatewhether the tool may run — grants and risk rules live server-side (deny by default: a tool nobody granted never runs, and the denial itself lands on the audit chain); - on
allow, executes locally and reports the outcome (complete), so the audit chain records the result; - on
blocked, raisesGovernanceDenied(reason); - on L2/L3 risk, raises
GovernancePendingApproval— wire it to your framework's human-in-the-loop.
LangGraph / CrewAI: the interrupt pattern
@gov.wrap_tool(name="demo.send_followup_email")
def send_email(customer_id: str, subject: str): ...
try:
send_email("C-1001", "quarterly check-in")
except GovernancePendingApproval as pending:
interrupt({"approval_id": pending.approval_id, "risk": pending.risk_level})
# ... after the human decides (console, API, anywhere):
gov.decide(pending.approval_id, "APPROVED")
result = gov.run_approved(send_email.__wrapped__, pending, "C-1001", "quarterly check-in")
Prefer to just block? wrap_tool(fn, wait=True) polls until a human decides
(approved executes + completes; rejected raises GovernanceDenied).
Running the sidecar
cd governance/packages/sidecar
SIDECAR_GATE_ALLOWED_TOOLS="crm.update_customer,demo.send_followup_email" \
SIDECAR_PGDATABASE=nexusclaw_sidecar pnpm exec tsx scripts/dev-server.ts
The console at http://127.0.0.1:7899/console shows pending approvals and
the audit chain (execution → tool calls → outbox events).
Tests
python3 -m unittest discover -s test # offline (stubbed transport)
python3 scripts/integration_test.py http://127.0.0.1:7899 # live sidecar
Metadata
Release files for nexusclaw-agent-governance 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nexusclaw_agent_governance-0.1.0.tar.gz | 7.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nexusclaw_agent_governance-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.5 kB
Release files / nexusclaw_agent_governance-0.1.0.tar.gz
| Download URL | nexusclaw_agent_governance-0.1.0.tar.gz |
|---|---|
| Size | 7.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
450b154fe459d5ebd45de437126e444eb46fd7f60da48668239f94d8f26dd792
|
|
BLAKE2b-256 checksum How to use checksums |
d727185de1cea9f6356a2b769e3e917cec7b68b262f1013bb0faed0cbc040111
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.5
|
Release files / nexusclaw_agent_governance-0.1.0-py3-none-any.whl
| Download URL | nexusclaw_agent_governance-0.1.0-py3-none-any.whl |
|---|---|
| Size | 6.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3fbce8e1aaeb049b1b4dd75ba3bd7299361c8d7aa4c875d07061043ea7bbc21a
|
|
BLAKE2b-256 checksum How to use checksums |
550828af383a1fbc2d65b989c70afb14a516779498b08e81b065c0af838519ef
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.5
|