CAIN-42 CAIN Studio

Recipes

Guard deployments

For an agent that ships code, in 15 frameworks.

Last reviewed 2026-10-02

Staging deploys run on their own; production waits for a person.

The rule

{
  "name": "deploy-guard",
  "effect": "require_approval",
  "priority": 10,
  "match_path": "/tools/deploy_service",
  "conditions": [
    {
      "field": "environment",
      "op": "eq",
      "value": "production"
    }
  ]
}

Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.

Risky{"service": "billing", "environment": "production"}
Safe{"service": "billing", "environment": "staging"}

Pick your framework

FrameworkTool name CAIN seesPlugs into
Python (any function)deploy_servicethe function that acts
LangChaindeploy_serviceyour agent's tool list
LangGraphdeploy_servicethe tools your graph's nodes call
OpenAI Agents SDKdeploy_servicefunction tools
CrewAIdeploy_serviceCrewAI's before-tool-call hooks
LlamaIndexdeploy_serviceFunctionTool
Pydantic AIdeploy_servicean agent capability
AutoGen (agentchat)deploy_servicethe callables you give AssistantAgent
Google ADKdeploy_servicethe functions in an agent's tools
Claude Agent SDKmcp__ops__deploy_servicePreToolUse hooks
MCP client (Python)deploy_serviceany MCP client session
OpenTelemetrydeploy_serviceyour existing tracing
Any other frameworkdeploy_serviceany Python callable
TypeScript / JavaScriptdeploy_serviceany async function
HTTP (any language)deploy_serviceyour own call site

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem