Arcezia

Arcezia / Integrations / OpenAI function calling

OpenAI function calling: check each call before it runs

Pass each OpenAI function call through ArceziaGuard before you run it. Your function runs only on ALLOW.

Setup

Before this: install the SDK, get a key and register a contract for your tool, as in Quickstart steps 1 to 5. SQL below is the contract domain from that Quickstart, and private_key is your signing key. Make one client and open the session:

from arcezia import Arcezia

az = Arcezia(task="look up orders", on_error="review", signing_key=private_key)
az.start_session(capability_envelope={
    "allowed_domains": [SQL],
    "allowed_action_types": ["execute_sql"],
    "resource_scope": ["orders"],
})

Check the call

from arcezia.integrations.openai import ArceziaGuard

r = ArceziaGuard(az).execute_tool_call(
    {"name": "execute_sql", "arguments": '{"query": "SELECT COUNT(*) FROM orders"}'},
    {"execute_sql": db.execute},
    {"execute_sql": SQL},
)
if r["needs_review"]:  ask_a_person(r["cert"].summary)
elif r["blocked"]:     raise RuntimeError(r["cert"].summary)
else:                  use(r["result"])

Check needs_review first. A hold comes back with both blocked and needs_review set. Read needs_review first.

What you get

On a new key a call usually comes back REVIEW first. The answer names what would release it, for example a contract for the tool or a signed scope for the session. See Handling the answers.

Same answers everywhere. Every hookup calls the same service with the same rules. Switching frameworks does not change a verdict.