Zero-Config Observe Mode
observe() is the easiest way to start with TealTiger. One function call, no configuration, immediate visibility into your agent’s behavior.
Progressive Disclosure
TealTiger follows a four-level progressive disclosure path. You start at Level 0 and graduate when you’re ready:
Each level is additive. Level 1 includes everything from Level 0. Level 2 includes everything from Level 1. You never lose capabilities by graduating.
How observe() Works Internally
When you callobserve(client), TealTiger creates a transparent proxy around your provider client:
Key Properties
- Transparent: The proxy exposes the same API surface as the original client. Every method, every parameter, every response — identical.
- Non-blocking: Nothing is ever blocked in observe mode. PII detection logs findings but never interferes with the request.
- In-process: No network calls, no proxies, no sidecars, no external services. Everything runs in your process.
- Deterministic: No LLM in the governance path. Same input always produces the same instrumentation behavior.
- Low overhead: Less than 5ms added per request (P99). The provider network call dominates total latency.
Proxy Wrapping
The proxy uses language-native mechanisms to intercept method calls:- TypeScript: ES6 Proxy with handler traps for
getandapply - Python:
__getattr__delegation with async/sync method detection
chat.completions.create, messages.create) and instruments only those. Utility methods, configuration setters, and non-API methods pass through with zero overhead.
Cost Accumulator
The cost accumulator extracts token usage from provider responses and computes cost using TealTiger’s built-in pricing database:- Per-request: Individual call cost
- Per-session: Sum of all requests in this
observe()session - Per-agent: Sum of all requests across all sessions for this
agentId
pricing_unavailable flag.
PII Scanner
The PII scanner uses TealTiger’s existingPIIDetectionGuardrail running in REPORT_ONLY mode:
- Scans both inputs and outputs for every request
- Detects: Email addresses, phone numbers, SSNs, credit card numbers
- Never blocks: Even if PII is found, the request proceeds normally
- Logs findings: PII type, count, and request ID written to audit log (never the PII values themselves)
- Fails silently: If the scanner errors internally, the request continues as if no scan occurred
Baseline Construction
The behavioral baseline automatically builds a statistical profile of your agent’s “normal” behavior:- Collects metrics for the first N requests (default: 100)
- Records: latency, input tokens, output tokens, cost, tool call count
- Once N requests are processed, computes p50, p95, p99 for each metric
- Marks the baseline as complete and writes a
baseline_completeaudit event
When to Use observe() vs Explicit Governance
The general rule: if you know what to block, use policies. If you don’t yet, use observe.
Supported Providers
observe() supports all 14 LLM provider clients:
If an unsupported client is passed,
observe() throws an UnsupportedProviderError identifying the type.
Air-Gapped and Offline Deployment
observe() works in air-gapped environments with no internet connectivity. It:
- Makes zero outbound network calls for instrumentation
- Does not require a proxy, sidecar, or external service
- Does not phone home, check licenses, or download updates
- Stores all data in-process (memory + local audit output)

