Skip to main content

TealTiger v1.4: Zero-Config Observe Mode

Getting started with governance shouldn’t require writing policies first. That’s been the biggest piece of feedback we’ve heard from the community since launching TealTiger: “I love the idea of deterministic governance, but I don’t want to write a policy file before I even know what my agent does.” Fair point. Today we’re shipping the answer.

The Problem: Governance Has an Adoption Problem

Every governance tool on the market asks you to define rules before you understand your system. Write policies. Configure thresholds. Define roles. Set budgets. But here’s the reality: most teams don’t know what “normal” looks like for their agents yet. They’re still iterating on prompts, testing tool integrations, and figuring out cost patterns. Asking them to write governance policies is like asking them to write tests for code they haven’t written yet. So we asked: what if governance started with observation, not enforcement?

Introducing observe() — Level 0

Three lines. No config files. No policy definitions. No external services. Everything runs in-process, deterministically, offline-capable. observe() is Level 0 of TealTiger’s progressive disclosure path: Each level builds on the previous. You graduate when you’re ready, not when the tool forces you.

What observe() Does Under the Hood

When you call observe(client), TealTiger wraps your provider client in a transparent proxy. Every method call passes through unchanged — same API, same responses, same errors. But behind the scenes:
  1. Cost Accumulator records token usage and computes cost using provider pricing models
  2. Audit Logger writes structured events for every request, response, error, and tool call
  3. PII Scanner detects sensitive data in inputs and outputs (report-only, never blocks)
  4. Baseline Builder collects latency, cost, and token statistics for the first 100 requests
The proxy adds less than 5ms overhead (P99). No network calls. No LLM in the governance path. Pure deterministic instrumentation.

The Kill Switch: freeze() and unfreeze()

Even in observe mode, you need an emergency stop. That’s what freeze() provides: freeze/unfreeze kill switch mechanism
No policies needed. No configuration. Just an immediate, in-memory kill switch that blocks all subsequent requests for the targeted agent(s).

Feature 2: Multi-Stage Defense Pipeline

TealGuard now offers configurable defense depth:
Stage 1 — Pattern Scanning (< 5ms): PII regex, secret patterns, injection signatures. Fast, deterministic, catches the obvious stuff. Stage 2 — Structural Analysis (< 20ms): AST-based intent classification for code outputs. Sentence-structure anomaly detection for natural language. Stage 3 — Local Classifier (< 50ms): A pre-trained ONNX binary classifier for harmful content. No LLM — just a lightweight model running locally. The pipeline short-circuits: if Stage 1 denies, Stages 2 and 3 never execute. You only pay the latency cost for the depth you actually need.

Feature 3: Post-Execution Response Governance

Until now, TealTiger scanned inputs. v1.4 adds output scanning:
Pre-execution: Block dangerous inputs before they reach the LLM. Post-execution: Block sensitive outputs before they reach the caller. Use cases:
  • Model outputs containing API keys or secrets it was trained on
  • PII that appears in completions (names, emails, phone numbers)
  • Harmful content generated by the model
The post-scan runs after the provider response but before it’s returned to your code. In ENFORCE mode, blocked content never reaches your application.

Feature 4: Role-Based Per-Agent Governance

Multi-agent systems need differentiated governance. A researcher agent needs different permissions than a writer agent:
Unrecognized roles are denied by default when default_deny: true is set. Each tool call is checked against the caller’s role. Least privilege, enforced automatically.

Feature 5: Governance Dashboard

Real-time visibility into everything governance does:
  • Agent Matrix: See all agents, their roles, status, cost, denial rates
  • Cost Panel: Burn rate, budget forecast, optimization suggestions
  • Defense Pipeline: Funnel visualization of Stage 1 → 2 → 3
  • Audit Trail: Chronological event log with full-text search
  • Evidence Viewer: Deep-dive into any TEEC evidence envelope
  • Policy Editor: Visual policy creation without touching JSON
  • Settings: Configure budgets and thresholds from the UI
The dashboard runs locally (Next.js + Fastify + SQLite). No cloud dependency. Your governance data stays on your infrastructure.

Getting Started

That’s it. You’re governed.

What’s Next

v1.4 is the foundation for TealTiger’s progressive disclosure story. In the coming weeks:
  • OpenAI Cookbook update with observe() as the primary entry point
  • langchain-tealtiger v0.2 with zero-config middleware mode
  • New adapters: llamaindex-tealtiger, autogen-tealtiger
  • Dashboard hosted mode for teams that want managed infrastructure
We believe governance should meet you where you are — not where it thinks you should be. Start with observe. Graduate when you’re ready.