Custom Pipelines
Custom pipelines¶
Explicit guard¶
For finer control, authorise inside the tool itself with the explicit client. authorize() returns a Decision: execute only on allowed, wait() holds an escalated action until a human decides in the dashboard, and raise_for_decision() raises PolicyBlocked / PolicyEscalated / SessionTerminated.
from xybern import Xybern
xy = Xybern(agent_id="pipeline-worker")
xy.start_session(budgets={"max_actions": 500, "ttl_seconds": 3600}) # live budget + kill switch
for step in plan:
d = xy.authorize(step.action, resource=step.resource, context=step.context)
if d.terminated:
break # the run was killed from the dashboard
if d.escalated:
d = d.wait(timeout=1800)
if d.allowed:
execute(step)
# every decision is sealed: xy.receipt(d.decision_id) returns the verifiable receipt
xy.end_session()
The REST payload underneath is documented in the Quick Start: action_type plus optional action_content, metadata, agent_id; decisions come back lowercase as allow, block, escalate or terminate.