Skip to main content

Runtime policy enforcement for LLM agent tool calls on Kubernetes.

Reason this release was yanked:

Incomplete release: the Helm chart was published unsigned. Use 0.1.2 or later.

Project description

Norviq

Runtime policy enforcement for LLM agent tool calls.

License Docs

Norviq is a policy enforcement point (PEP) that sits between an agent's reasoning loop and the tools it can call. Every tool call is evaluated against OPA/Rego policy and then allowed, blocked, escalated, or auditedbefore the tool function runs. It turns "the model decided to call execute_sql" from implicit trust into an enforced, auditable decision.

This package is the Python SDK: it wraps your existing tools so enforcement happens in-process. The full platform (control plane, console, Kubernetes admission webhook, sidecar injection) is installed with the Helm chart — see the documentation.

Install

pip install "norviq[langchain]"      # LangChain / LangGraph
pip install "norviq[crewai]"         # CrewAI
pip install "norviq[autogen]"        # AutoGen
pip install "norviq[semantic-kernel]" # Semantic Kernel
pip install "norviq[frameworks]"     # all of the above

Use

from norviq.sdk import PolicyEngineClient, ToolInterceptor
from norviq.sdk.langchain.adapter import protect

engine = PolicyEngineClient()                      # NRVQ_POLICY_ENGINE_URL + NRVQ_API_TOKEN
interceptor = ToolInterceptor(evaluator=engine)

# Every tool is wrapped: policy runs before the tool body, on every call the model makes.
tools = protect([search_kb, execute_sql, delete_record], interceptor, session_id="session-1")

A blocked call raises NorviqBlockError, which carries the full PolicyDecision — including the rule_id that fired and a human-readable reason — so you can surface a refusal instead of performing the action:

from norviq.sdk import NorviqBlockError

try:
    result = agent.invoke({"messages": [("user", "delete all customer records")]})
except NorviqBlockError as exc:
    print(f"blocked by {exc.decision.rule_id}: {exc.decision.reason}")

Two things to know before your first run, because either one makes a correct setup look broken:

  • Norviq is deny-by-default. With no policy loaded for the scope you evaluate against, the decision is deny. Load a policy for your namespace/agent-class first.
  • POST /api/v1/evaluate requires a bearer token. Without one the client fails closed.

Links

Apache 2.0 licensed.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

norviq-0.1.1.tar.gz (367.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

norviq-0.1.1-py3-none-any.whl (430.1 kB view details)

Uploaded Python 3

File details

Details for the file norviq-0.1.1.tar.gz.

File metadata

  • Download URL: norviq-0.1.1.tar.gz
  • Upload date:
  • Size: 367.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for norviq-0.1.1.tar.gz
Algorithm Hash digest
SHA256 af41a3bcd1f8e445cdd1ccdc1df4a841926cbffa8780d8fbaa6bf416456b30a8
MD5 049473b48eabe3ae9969c3dd211f39ff
BLAKE2b-256 7da450ab7ca262a4916b59d5ad44940d97463f9521856a9f1be4db34d7c39f56

See more details on using hashes here.

Provenance

The following attestation bundles were made for norviq-0.1.1.tar.gz:

Publisher: pypi-publish.yml on norviq-dev/norviq

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file norviq-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: norviq-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 430.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for norviq-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 3cf41192392b627820619d6eeb5d00eab9721c27cd8a69205637c0b6de09104a
MD5 9ef35a2b57abdeba418c5f6e1405a95c
BLAKE2b-256 a073a07ba5f96df68d4c363b9c52a01a63544d4aa64e61b837bbd1a35332cb4e

See more details on using hashes here.

Provenance

The following attestation bundles were made for norviq-0.1.1-py3-none-any.whl:

Publisher: pypi-publish.yml on norviq-dev/norviq

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page