- Preface
- How to Use This Book and the Companion Repository
- Part I: Foundations
- Chapter 1. The Model Proposes, the Guardrail Decides What an agent is, what a guardrail is, and why an agent needs both
- Chapter 2. A Map of Guardrails Input, action, risk, approval, memory, retrieval, plan, output and cumulative guardrails, and where each one sits in the agent graph
- Chapter 3. Guardrails Are Just Functions Deterministic, fail-closed functions with reason codes, and how to test them without calling the model
- Part II: Core Guardrails
- Chapter 4. The Guard at the Door Program 01: PII Input Guardrail
- Chapter 5. Ask First, Act Later Program 02: Financial Action Guardrail
- Chapter 6. Not All Risk Is Equal Program 03: Risk Routing Guardrail
- Chapter 7. When in Doubt, Ask a Person Program 04: Human Approval Guardrail
- Chapter 8. Seeing Is Not Remembering Program 05: Memory Guardrail
- Chapter 9. Found Is Not Trusted Program 06: Retrieval Guardrail
- Chapter 10. Look Before the Whole Journey Program 07: Plan Guardrail
- Chapter 11. The Last Checkpoint Program 08: Output Guardrail
- Chapter 12. When Small Things Add Up Program 09: Blast Radius Guardrail
- Part III: Production Guardrails — Coming in Future Updates
- Chapter 13. Trust Boundaries Program 10: Tool Output, MCP Tool Trust and Data Egress Guardrails
- Chapter 14. Who and How Much Program 11: Authorization and Loop & Budget Guardrails
- Chapter 15. Exactly Once Program 12: Idempotency and Approval Integrity Guardrails
- Chapter 16. Beyond Regex Program 13: Classifier Guardrails and Multi-Turn Escalation
- Chapter 17. Say Only What You Can Prove Program 14: Grounding and SQL Query Guardrails
- Chapter 18. The Guardrail Gateway Program 15: Circuit Breaker, Audit Trail and Policy Gateway
- Appendices
- Appendix A. Guardrail Reference Card
- Appendix B. Guardrail Checklist for Design Reviews
- Appendix C. Mapping to the OWASP Top 10 for LLM Applications
- Appendix D. Production Rollout Notes
- Appendix E. From Regex to Production Libraries
Guardrails for AI Agents
Building agents that act safely in production, with Python, LangGraph and LLM
Nine small LangGraph agents, each adding one guardrail: PII, financial actions, risk routing, human approval, memory, retrieval, plans, output and cumulative limits. Plain Python, fully tested, no theory.
Minimum price
$10.00
$15.00
You pay
Author earns
About
About the Book
Most agent tutorials show you how to make an agent act. This one shows you how to stop it.
A model that can issue refunds, send messages or update records will eventually try to do the wrong one. The usual defence is a sentence in a prompt, and a sentence in a prompt is a request, not a rule. This book takes a different approach, built on one idea:
The model proposes. The guardrail decides. The tool executes.
You build nine small, working LangGraph agents, each adding a guardrail at a new point:
- Input — clean sensitive data before the model ever sees it
- Action — check a tool call before the tool runs
- Risk routing — send low, medium and high risk down different paths
- Human approval — pause the agent mid run and let a person decide
- Memory — stop the wrong things being remembered forever
- Retrieval — filter documents by permission, and catch instructions hidden inside them
- Plan — approve a whole sequence before the first step runs
- Output — read the answer before the customer does
- Blast radius — catch the hundred small actions that add up to one large problem
Every guardrail is plain Python: predictable, testable in milliseconds without an API key, and impossible to talk out of doing its job. Every chapter opens with a real failure, shows the code that prevents it, tests it, and then tells you honestly what it still does not catch.
Who this is for
Engineers building or reviewing agents that do something real. You need to read Python. You do not need LangGraph or a security background. The policy files and tests are plain enough to show to a manager, a risk officer or an auditor, and several chapters suggest doing exactly that.
What you get
- 12 complete chapters
- A companion repository with all nine programs and a full test suite
- A one page reference card listing every guardrail in a single line
Still growing
Part III, Production Guardrails, is being added one chapter at a time: trust boundaries, authorization and budgets, idempotency, classifier based checks, grounding, and a shared policy gateway. Everyone who owns the book gets every update at no extra cost.
The examples run on Claude, and every guardrail is plain Python that works with any model.
Companion repository: github.com/sameershukla/guarded-agents-in-action
Author
About the Author
I’m Sameer Shukla, Director of Data & AI Architecture at IntraEdge, author of two books on AI systems, and a long-time technical writer and community contributor. My work spans production-grade AI, data engineering, and agentic systems, with a focus on AWS, Snowflake, Python, and LangGraph. I’ve published extensively on software and data technologies, contributed to the Apache Airflow community, and was recognized as an Apache Airflow Contributor of the Month. I’m based in Irving, Texas.
Contents
Table of Contents
Get the free sample chapters
Click the buttons to get the free sample in PDF or EPUB, or read the sample online here
The Leanpub 60 Day 100% Happiness Guarantee
Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms...
Earn $8 on a $10 Purchase, and $16 on a $20 Purchase
We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.
(Yes, some authors have already earned much more than that on Leanpub.)
In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.
Learn more about writing on Leanpub
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them
Write and Publish on Leanpub
You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!
Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.
Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.