CAIN-42 CAIN Studio

Recipes

Guard email

For an agent that sends email, in 15 frameworks.

Last reviewed 2026-10-02

Mail inside your company runs; mail to anyone outside waits for a person. Recipients are also destinations: until you allow a destination under egress rules, the egress stage refuses it on its own.

The rule

{
  "name": "email-guard",
  "effect": "require_approval",
  "priority": 10,
  "match_path": "/tools/send_email",
  "conditions": [
    {
      "field": "to",
      "op": "not_contains",
      "value": "@yourcompany.com"
    }
  ]
}

Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.

Risky{"to": "someone@gmail.com", "subject": "Invoice", "body": "..."}
Safe{"to": "ops@yourcompany.com", "subject": "Invoice", "body": "..."}

Pick your framework

FrameworkTool name CAIN seesPlugs into
Python (any function)send_emailthe function that acts
LangChainsend_emailyour agent's tool list
LangGraphsend_emailthe tools your graph's nodes call
OpenAI Agents SDKsend_emailfunction tools
CrewAIsend_emailCrewAI's before-tool-call hooks
LlamaIndexsend_emailFunctionTool
Pydantic AIsend_emailan agent capability
AutoGen (agentchat)send_emailthe callables you give AssistantAgent
Google ADKsend_emailthe functions in an agent's tools
Claude Agent SDKmcp__ops__send_emailPreToolUse hooks
MCP client (Python)send_emailany MCP client session
OpenTelemetrysend_emailyour existing tracing
Any other frameworksend_emailany Python callable
TypeScript / JavaScriptsend_emailany async function
HTTP (any language)send_emailyour own call site

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem