CAIN-42 CAIN Studio

Recipes

Guard customer data

For an agent that exports records, in 15 frameworks.

Last reviewed 2026-10-02

An export that includes social security numbers is refused; other fields export. On a list, contains means one of the items equals the value.

The rule

{
  "name": "customer-data-guard",
  "effect": "deny",
  "priority": 10,
  "match_path": "/tools/export_customers",
  "conditions": [
    {
      "field": "fields",
      "op": "contains",
      "value": "ssn"
    }
  ]
}

Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.

Risky{"segment": "all", "fields": ["email", "ssn"]}
Safe{"segment": "all", "fields": ["email", "plan"]}

Pick your framework

FrameworkTool name CAIN seesPlugs into
Python (any function)export_customersthe function that acts
LangChainexport_customersyour agent's tool list
LangGraphexport_customersthe tools your graph's nodes call
OpenAI Agents SDKexport_customersfunction tools
CrewAIexport_customersCrewAI's before-tool-call hooks
LlamaIndexexport_customersFunctionTool
Pydantic AIexport_customersan agent capability
AutoGen (agentchat)export_customersthe callables you give AssistantAgent
Google ADKexport_customersthe functions in an agent's tools
Claude Agent SDKmcp__ops__export_customersPreToolUse hooks
MCP client (Python)export_customersany MCP client session
OpenTelemetryexport_customersyour existing tracing
Any other frameworkexport_customersany Python callable
TypeScript / JavaScriptexport_customersany async function
HTTP (any language)export_customersyour own call site

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem