Pipeline

The entry point of the guardrail service for the prompt pipeline.

GuardrailPipeline runs an LLMClient’s guardrails on the user’s message before it is sent to the LLM (run_pre()), and on the LLM’s reply before it is returned to the user (run_post()), and folds their outcomes into a single PipelineResult.

pipeline = GuardrailPipeline.for_llmclient(llmclient, session_key=session_key)
pre = pipeline.run_pre({"messages": messages})
if pre.blocked:
    return pre.message
messages = pre.payload["messages"]  # possibly redacted
response = call_llm(messages)
post = pipeline.run_post(response)
reply = post.message if post.blocked else post.payload

Note

Experimental. The Guardrail was designed and coded by Claude Code (Anthropic’s Claude Opus 5.5), with Lawrence McDaniel as co-author. It is experimental, and will be documented.

class smarter.apps.guardrail.services.pipeline.GuardrailPipeline(guardrails, *, llmclient=None, session_key=None, record_events=True)[source]

Bases: object

Run a set of guardrails on a prompt’s input and output.

The guardrails run one at a time, in order of priority then id, each on the payload as changed by the guardrails before it: e.g. an LLM judge that runs after a PII redaction guardrail sees the redacted text. The first guardrail that blocks stops the pipeline, so that no further, possibly costly, guardrails run.

A guardrail that fails to run, e.g. because its LLM provider is unavailable, is recorded, and skipped, unless it is failClosed, in which case it blocks.

Every triggered guardrail, and every failure, is recorded as a GuardrailEvent, unless record_events is false.

Parameters:
  • guardrails (Iterable[Guardrail]) – The guardrails. Inactive guardrails, and those of the other stage, are skipped.

  • llmclient (Any) – The LLMClient of the prompt, for the events.

  • session_key (Optional[str]) – The session key of the prompt, for the events.

  • record_events (bool) – Whether to record events. False for dry runs.

__init__(guardrails, *, llmclient=None, session_key=None, record_events=True)[source]
classmethod for_llmclient(llmclient, session_key=None)[source]

Return a pipeline for the guardrails of an LLMClient, as listed in its manifest’s spec.guardrails.

Return type:

GuardrailPipeline

guardrails_for(stage)[source]

Return the pipeline’s guardrails that run on a stage.

Return type:

list[Guardrail]

run_post(response_json, *, request_uid=None)[source]

Run the output guardrails on the reply of a chat completion response.

Parameters:

response_json (dict[str, Any]) – The response, with its choices.

Return type:

PipelineResult

Returns:

The result. Use its payload, which may be redacted, as the response.

run_pre(request_json, *, request_uid=None)[source]

Run the input guardrails on the latest user message of a chat completion request.

Parameters:

request_json (dict[str, Any]) – The request, with its messages.

Return type:

PipelineResult

Returns:

The result. Use its payload, which may be redacted, as the request.

smarter.apps.guardrail.services.pipeline.fold(current, incoming)[source]

Return whichever of two dispositions ranks higher.

Return type:

PipelineDisposition