LangChain + Tork Governance
Add on-device PII governance to your LangChain chains and agents. Govern prompts, generations, chain inputs and outputs, redact or deny by policy, and keep a local receipt for every decision.
Policy Enforcement
Block unsafe content automatically
Chain Governance
Wrap any LangChain chain
Tool Safety
Callbacks govern tool inputs and outputs
LCEL Support
Works with modern LangChain
Installation
Install Tork with LangChain dependencies.
The adapter ships inside the on-device package: import it from tork_governance.adapters.langchain. It exports exactly three names: TorkCallbackHandler, TorkGovernedChain and create_governed_chain. PII detection and the allow/redact/deny decision run on your machine; no API key is required.
TorkCallbackHandler
Monitor and govern all LangChain operations via callbacks.
The callback handler implements the LangChain callback method names and runsTork.govern() on every LLM prompt, LLM generation, tool input and tool output. Redacted text is written back in place; withblock_on_pii=True and a Tork configured withdefault_action=GovernanceAction.DENY, a denied prompt raisesValueError. Chain start/end hooks exist but are no-ops.
Callback Events
| on_llm_start | Evaluate prompts before sending to LLM |
| on_llm_end | Evaluate LLM responses |
| on_chain_start | No-op in 0.26.1 (use TorkGovernedChain for chain inputs) |
| on_chain_end | No-op in 0.26.1 (use TorkGovernedChain for chain outputs) |
| on_tool_start | Evaluate tool inputs |
| on_tool_end | Evaluate tool outputs |
TorkGovernedChain
Wrap any LangChain chain with governance controls.
TorkGovernedChain (or thecreate_governed_chain() factory) wraps any LangChain runnable. Every string value in the input is governed before chain.invoke(), and a string output or a message's .content is governed after. PII is redacted in place by default; a DENY decision raises ValueError.
Governing individual tools
What the adapter does and does not provide for tools.
The published adapter has no per-tool wrapper (there is no TorkGovernedTool). Tool inputs and outputs are governed as strings through the callback handler'son_tool_start / on_tool_end hooks, which record a receipt but do not stop the tool from running. To gate a side effect, callTork.govern() on the arguments inside the tool itself, as the AgentExecutor example below does for send_email.
LCEL Integration
Use with LangChain Expression Language (LCEL) chains.
Both patterns work with LCEL runnables. Use the callback handler to govern what the LLM sees and says, or TorkGovernedChain to govern the chain's own inputs and outputs.
AgentExecutor with Governance
Full governance for multi-step agent workflows.
Attach one callback handler to the LLM and the executor. Prompts, generations, tool inputs and tool outputs are each governed and receipted; gate side effects inside the tool body.
Policy Enforcement Patterns
Redact by default, deny when you choose to.
The on-device SDK has one decision rule: when PII is detected it applies the Tork instance'sdefault_action (REDACT unless you set DENY). A DENY insideTorkGovernedChain.invoke() raises a plainValueError; there is no custom exception class.
Advanced Patterns
Streaming, async, and compliance receipts
Best Practices
Use callbacks for the LLM boundary, TorkGovernedChain for the chain boundary
The handler governs prompts and generations; the wrapper governs the chain's inputs and outputs. Both redact in place.
Gate side effects inside the tool
Callbacks receipt tool I/O but do not stop a tool. Call Tork.govern() on the arguments before a database write, email or file change.
Handle ValueError from a DENY decision
With default_action=DENY the wrapper raises ValueError. Catch it and return a user-friendly message.
Persist handler.receipts yourself
Receipts are local objects. They reach the dashboard only with Tork(api_key=...) and then as client attestations.
Share one Tork instance
Pass the same Tork(policy_version=...) to every handler and wrapper so receipts carry one policy version.
Imports Reference
Next Steps
Configure policies in the dashboard and explore other integration options.