Integrations
EVE + LangGraph
Compatibility: Experimental integration — structurally implemented but not included in the supported release-candidate adapter matrix.
The LangGraph adapter routes tool calls made from graph nodes into EVE's governance composition root so CoreGuard makes a deterministic ALLOW / BLOCK / MODIFY decision before a tool executes. The adapter is structurally implemented, but LangGraph was not installed during release-candidate validation, so it was not validated against a pinned live version and is marked UNTESTED / experimental. Only the generic adapter is SUPPORTED.
How governance works here
A node's tool call is submitted to EVE before it runs. No LLM is in the decision path.
from eve_coreguard import CoreGuardClient
client = CoreGuardClient(api_key="eve_sk_...")
result = client.evaluate(
request_id="req-e6b0",
tenant_id="tenant_demo",
proposed_action={"type": "update_ticket", "ticket_id": "T-8842", "status": "closed"},
model_output={"decision": "call_tool", "confidence": 0.9},
context={"principal_id": "graph_agent", "session_id": "sess_e6b0"},
policy_set="tool_calls_v1",
)
# result.decision.status: ALLOWED -> execute; BLOCKED -> skip the tool; MODIFIED -> use result.decision.action.
eve-coreguard (0.2.7) is published on PyPI.
Entry point: the CoreGuardClient class.
Hardened alternative
This adapter is wrapper-enforced: a node that calls the underlying tool directly is not intercepted. For a boundary a direct call cannot route around:
- Put tools behind a restricted server-side tool registry reachable only through the governed path.
- Proxy tool execution through a sidecar so governance runs out-of-process.
- Apply network enforcement so tool endpoints are only reachable via the governed path.
- For MCP tools, route through the MCP gateway, which binds the approved request to the executed request (see mcp.md).
Readiness
- This adapter: experimental (UNTESTED against a pinned live LangGraph version; wrapper-enforced).
- Generic Python adapter: SUPPORTED.
- EVE SDK core: RELEASE CANDIDATE WITH EXCLUSIONS.
Limitations
- Not validated against a pinned live framework version.
- Wrapper-enforced: bypassable by a direct underlying-tool call. Hard enforcement requires a gateway/sidecar or restricted server-side tool registry.
- Hosted mode requires a reachable endpoint; embedded governance is the EVE service.
- Evidence verification proves authenticity and integrity, not decision correctness; independent verification needs the ECDSA P-384 public key.