← All Frameworks

CrewAI Guardrails

before_tool_call hook for multi-agent crew authorization

Python

CrewAI orchestrates autonomous AI agent crews for complex tasks. APort integrates via CrewAI's native before_tool_call hook system, enforcing OAP policies before any tool in any crew member executes.

Quick Start

1. Create passport & config

setup
npx @aporthq/aport-agent-guardrails crewai

2. Install guardrails package

install
pip install aport-agent-guardrails-crewai

3. Add to your code

code
from aport_guardrails_crewai import register_aport_guardrail

register_aport_guardrail()
crew.kickoff()

Test the authorization boundary

Installer target: crewai. Aliases: none; use the target ID.

CrewAI setup
npx @aporthq/aport-agent-guardrails crewai

Denied-action example

Read .env.aport-smoke-test with a passport that blocks .env* paths.

Expected policy result: deny. Use an empty test file. In warn mode the runtime may continue; enforce mode must stop the read. Hosted mode can record the decision; local mode does not prove hosted audit persistence.

Expected policy result, illustrative
{
  "policy_id": "data.file.read.v1",
  "allow": false,
  "reason": "oap.blocked_pattern"
}

How It Works

1

Passport

Your agent gets an OAP passport declaring its identity, capabilities, and operational limits.

2

Evaluate

Before every tool call, the guardrail evaluates it against the passport's policy. Locally or via hosted API.

3

Decision

Allow or deny with structured OAP reason codes. Signed decisions create an auditable trail.

Frequently Asked Questions

How do CrewAI guardrails work?

APort registers a before_tool_call hook that runs before every tool execution across all agents in a crew. If the tool call violates the passport's policy, it's blocked before execution.

Does this work across all agents in a crew?

Yes. The hook is registered globally, so it applies to every agent in the crew regardless of role or task assignment.

Ready to secure your CrewAI agents?

Review the setup command and denied-action check before enforcing policy.

Start free for local or individual setup. Upgrade to Team for hosted org audit, signed decisions, GitHub guardrails, and shared enforcement across your team.