Python SDK
Enforce a budget
core.eve_sdk (an EVE(...) object with govern_* methods). That module is not present in the current repository and is not published on any registry, so these snippets raise ModuleNotFoundError if run. They are kept because they show the intended governance flow. For code that runs today, use the published client: pip install eve-coreguard, then from eve_coreguard import CoreGuardClient and call client.evaluate(...), with offline evidence checking via client.verify_evidence(...) or the standalone verify_decision_record. See the CoreGuard integration guide and the Python SDK reference.Set deterministic budget and resource limits on an agent so a permitted call executes until the configured limit is reached, then further calls are blocked. Budgets are computed by deterministic counters, not by a model.
Prerequisites
- The EVE embedded service facade (
from core.eve_sdk import EVE) or a hosted/sidecar endpoint. - A shared store (for example PostgreSQL) if you need durable budgets across instances.
- Synthetic tools only; no production credentials.
Installation
pip install eve-coreguard
# or run the embedded facade from the EVE repo
Runnable code
Budget controls are part of EVE agent governance. Conceptually, configure a limit and govern each call; once the counter reaches the limit, the decision blocks:
from core.eve_sdk import EVE
IDENT = {"tenant_id": "acme", "principal_id": "agent-1", "session_id": "sess-1"}
eve = EVE(policy="lending_v1", mode="embedded")
# Each governed call increments the deterministic budget counter for this
# session/principal. When consumed reaches the configured limit, EVE blocks.
for i in range(5):
d = eve.govern_tool_call(tool="external_lookup", arguments={"i": i}, context=IDENT)
print(i, d.action, d.allowed)
if not d.allowed:
print("budget exceeded:", d.reason_codes)
break
Expected result
- Calls up to the configured limit return
ALLOW. - The first call that would exceed the limit returns
BLOCKwith a budget reason code; the tool does not run.
Evidence output
budget finding {limit: <N>, consumed: <N>, exceeded: true}
The finding is deterministic — the same call sequence yields the same limit/consumed values.
Verification
The budget decision carries a signed certificate; verify it offline like any EVE evidence (see verify-evidence-offline.md).
Failure example
In the pilot, budget counters are in-process per session/principal. Two separate instances without a shared store each keep their own counter, so a global limit is not enforced across them until you back the counter with a shared store.
Production considerations
- For a limit that spans processes or hosts, back the budget counter with a shared store (for example PostgreSQL); in-process counters are per-instance.
- Choose limits per principal and per session so a single agent cannot exhaust another's budget.
- Treat a budget BLOCK as terminal for that call.
Limitations
- Budget controls are PILOT_READY. Counters are deterministic, but durable cross-instance budgets require a shared store; in-process counters are per-instance in the pilot.
- Budget enforcement governs whether a permitted call may still execute; it is one deterministic control alongside CoreGuard, sequence, and anomaly controls.
Next step
Block dangerous multi-step chains with block-a-prohibited-sequence.md, or watch for drift with detect-behavioral-anomalies.md.