CrewAI + Tork Governance
Add PII guardrails to your CrewAI multi-agent systems. Govern task inputs, tool calls and crew outputs on-device, with a local receipt for every decision.
Crew Governance
Wrap entire crews with one call
Agent Control
Govern individual agents
Task Validation
Check inputs and outputs
Local Receipts
A receipt for every check, on-device
Installation
Install Tork with CrewAI dependencies.
CrewAI adapters are in tork_governance.adapters.crewai. Governance runs on-device: PII detection and the allow / redact / deny decision are computed locally.
TorkCrewAIMiddleware
The main entry point for CrewAI governance.
The middleware wraps agents and crews. A wrapped agent governs the task description before execute_task() runs and the output after; a wrapped crew governs thekickoff() inputs and the final output. Each check appends a receipt summary tomiddleware.receipts.
Middleware Methods
| wrap_agent() | Wrap a single agent (returns GovernedAgent) |
| wrap_crew() | Wrap a crew (returns GovernedCrew) |
| process_input() / process_output() | Govern text; returns a GovernanceResult with a receipt |
| check_tool_call() | Govern a tool name + arguments before execution |
GovernedAgent
Wrap individual CrewAI agents with governance controls.
GovernedAgent wraps a single agent to validate task inputs before execution and check outputs after. Use when you need granular control over specific agents.
GovernedCrew
Wrap entire CrewAI crews for comprehensive governance.
GovernedCrew governs the string inputs you pass tokickoff() and the crew's final output. It does not wrap the individual agents inside the crew; wrap those with GovernedAgent if you need per-task checks.
Per-Task Checks
Govern a task description, an output, or a tool call directly.
There is no task wrapper class. For fine-grained control call the middleware'sprocess_input(), process_output() andcheck_tool_call() yourself. Each returns aGovernanceResult (action, output, pii, receipt).
Complete Workflow Example
A production-ready customer service crew with full governance.
Inter-Agent Communication
Governance for agent delegation and collaboration.
The adapter does not intercept messages that CrewAI agents exchange with each other during delegation (allow_delegation=True, hierarchical processes). It governs what enters a crew or agent (inputs, task descriptions) and what leaves it (outputs). To govern an internal hand-off, pass the text throughmiddleware.process_input() yourself before the receiving agent uses it.
Error Handling
Handle governance violations gracefully.
The adapter raises a plain ValueError when governance denies an input, and only when the engine's action is DENY. With the defaultREDACT action nothing is raised: PII is replaced in place.
Exception Types
| ValueError | Raised by execute_task() / kickoff() when an input is denied; the message carries the receipt id |
| (no other exceptions) | There are no toxicity, jailbreak or policy exception types in this adapter |
Advanced Topics
Compliance receipts and configuration
Best Practices
Use GovernedCrew for simplicity
Wrapping the entire crew is easier and ensures all agents are governed consistently.
Handle ValueError when using DENY
With Tork(default_action=GovernanceAction.DENY) the adapter raises ValueError on denied input; catch it to respond gracefully.
Set meaningful agent IDs
Use descriptive agent_id values to identify which crew/agent triggered violations in logs.
Keep the local receipts
Every check appends a summary to middleware.receipts; the full on-device receipt is on each GovernanceResult.
Start with DENY, relax to REDACT
Run with default_action=DENY in staging to see what would be blocked, then switch to REDACT for production.
Imports Reference
Next Steps
Configure policies in the dashboard or explore other framework integrations.