Recipes
Guard email
For an agent that sends email, in 15 frameworks.
Last reviewed 2026-10-02
Mail inside your company runs; mail to anyone outside waits for a person. Recipients are also destinations: until you allow a destination under egress rules, the egress stage refuses it on its own.
The rule
{
"name": "email-guard",
"effect": "require_approval",
"priority": 10,
"match_path": "/tools/send_email",
"conditions": [
{
"field": "to",
"op": "not_contains",
"value": "@yourcompany.com"
}
]
}Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.
| Risky | {"to": "someone@gmail.com", "subject": "Invoice", "body": "..."} |
|---|---|
| Safe | {"to": "ops@yourcompany.com", "subject": "Invoice", "body": "..."} |
Pick your framework
| Framework | Tool name CAIN sees | Plugs into |
|---|---|---|
| Python (any function) | send_email | the function that acts |
| LangChain | send_email | your agent's tool list |
| LangGraph | send_email | the tools your graph's nodes call |
| OpenAI Agents SDK | send_email | function tools |
| CrewAI | send_email | CrewAI's before-tool-call hooks |
| LlamaIndex | send_email | FunctionTool |
| Pydantic AI | send_email | an agent capability |
| AutoGen (agentchat) | send_email | the callables you give AssistantAgent |
| Google ADK | send_email | the functions in an agent's tools |
| Claude Agent SDK | mcp__ops__send_email | PreToolUse hooks |
| MCP client (Python) | send_email | any MCP client session |
| OpenTelemetry | send_email | your existing tracing |
| Any other framework | send_email | any Python callable |
| TypeScript / JavaScript | send_email | any async function |
| HTTP (any language) | send_email | your own call site |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem