AutoGen + Tork Governance
Add PII guardrails to Microsoft AutoGen conversations. Govern the messages that enter and leave your agents on-device, scan tool results, and keep a local receipt for every decision.
Message Governance
PII redacted on wrapped agents
Local Receipts
A receipt for every governed message
On-Device
No network calls without an api_key
Tool Result Scanning
PII and injection checks on results
Installation
Install Tork with AutoGen dependencies.
AutoGen adapters are in tork_governance.adapters.autogen. Governance runs on-device: PII detection and the allow / redact / deny decision are computed locally.
TorkAutoGenMiddleware
Central middleware for governing AutoGen agent conversations.
The middleware wraps an AutoGen agent so that the messages it sends, receives, initiates and generates through the wrapper are governed for PII. Use wrap_agent()to wrap any agent, or govern_message() /process_message() to govern text directly.
GovernedAutoGenAgent
The wrapper wrap_agent() returns; construct it directly for explicit control.
GovernedAutoGenAgent governs send(),receive(), initiate_chat() andgenerate_reply(). Denied outgoing messages raise a plainValueError; incoming messages and replies are redacted, never raised on. Every other attribute is delegated to the wrapped agent.
Governed GroupChat
Govern multi-agent team conversations.
There is no group-chat wrapper in the adapter. You can govern the seed messages withcreate_message_filter() and the opening message by wrapping the agent that starts the chat. Messages the agents exchange inside the group are not intercepted.
Code Execution
What the adapter does and does not do for executed code.
AutoGen can execute code generated by agents. The adapter does not inspect or block that code: there is no import allowlist, no dangerous-operation policy, and dashboard policies are not applied on-device. What it does is scan the text that passes through a wrapped agent for PII. Keep AutoGen's own code_execution_config (Docker, work_dir) as your execution sandbox.
Tool Arguments and Results
Scan tool arguments and tool results for PII and prompt injection.
There is no validate_tool_call() and no SQL or recipient policy. What exists: govern serialised tool arguments with process_message() (PII detection), and scan a tool's result with Tork.scan_tool_result()for PII and prompt-injection text before it is appended to the model context.
Error Handling
Handle governance violations gracefully.
The adapter raises a plain ValueError fromsend() and initiate_chat() when the outgoing message is denied, and only when the engine's action is DENY. With the default REDACT action nothing is raised. There are no custom exception classes and no jailbreak detection in this adapter.
Multi-Agent Workflow
Complete example of a governed customer service team.
A customer service team with specialized agents. The comments in the sample state exactly which messages are governed: the opening message and any text you pass throughgovern_message(), not the traffic inside the group chat.
Advanced Patterns
Local receipts and async usage
Best Practices
Govern at the boundaries
Wrap the agent that starts a chat and govern final answers with govern_message(); the adapter does not intercept intra-group traffic.
Sandbox code execution with AutoGen
Use code_execution_config (Docker, work_dir) for isolation; the adapter does not inspect generated code.
Scan tool results before they reach the model
Use Tork.scan_tool_result() on every external result; set block_on_injection=True for untrusted sources.
Handle ValueError when using DENY
With Tork(default_action=GovernanceAction.DENY) the adapter raises ValueError on denied messages; catch it to respond gracefully.
Keep the local receipts
Every governed message appends a summary to middleware.receipts; the full on-device receipt is on each GovernanceResult.
Imports Reference
Next Steps
Configure policies in the dashboard and explore other framework integrations.