Skip to main content
Integrate TealTiger with Strands Agents to add deterministic governance to your production agents. The strands-tealtiger package ships as a native Strands plugin — no external server, no LLM in the governance path, under 2ms per evaluation.

Why integrate TealTiger with Strands?

Strands Agents gives you a model-driven agent loop with lifecycle hooks and a plugin system. TealTiger plugs into that system to add:
  • Tool authorization — Allowlist and blocklist which tools the agent can call
  • PII protection — Block tool calls containing SSNs, credit cards, emails, or phone numbers
  • Secret detection — Catch API keys, tokens, and credentials before they leak
  • Prompt injection defense — Detect adversarial inputs in tool arguments
  • Cost budgets — Hard-stop when session spend exceeds your limit
  • Kill switch — Freeze all tool calls instantly without restarting
  • Structured audit trail — Every decision produces a traceable record

Installation

Quick start

Configuration

Tool allowlist and blocklist

Control which tools the agent can call using glob patterns:

PII detection

Block tool calls containing sensitive data in their arguments:

Secret detection

Block tool calls containing API keys, tokens, or credentials:
Detects: OpenAI keys (sk-...), GitHub tokens (ghp_...), AWS keys (AKIA...), Slack tokens, generic API keys, and PEM private keys.

Prompt injection defense

Detect adversarial inputs in tool arguments before they reach the model:
Catches 8 attack patterns: instruction override, DAN/jailbreak, developer mode, system prompt override, delimiter injection, XML tag injection, fake system messages, and jailbreak keywords.

Cost budget

Hard-stop when session cost exceeds your limit:

Kill switch

Freeze all tool calls immediately — no policy can override:

Governance modes

Start with OBSERVE when deploying, promote to MONITOR to see what would be blocked, then switch to ENFORCE in production:

Audit trail

Every evaluation produces a structured GovernanceDecision:

Multi-agent support

Works with Strands multi-agent patterns (Swarm, Graph). Attach the plugin to individual agents:

Complete example

How it works

TealTiger implements the Strands Plugin interface with two @hook methods:
  1. BeforeToolsEvent — Kill switch enforcement at the batch level. If frozen, cancels the entire batch.
  2. BeforeToolCallEvent — Per-tool policy evaluation. Checks allowlist, blocklist, injection, PII, secrets, and budget in sequence. First violation wins.
Evaluation order:
  1. Kill switch (risk: 100)
  2. Budget limit (risk: 70)
  3. Blocked tools (risk: 90)
  4. Allowed tools (risk: 80)
  5. Prompt injection (risk: 95)
  6. PII detection (risk: 90)
  7. Secret detection (risk: 95)

Comparison with Agent Control

API reference

Constructor parameters

Methods

Properties

Next steps