Retrieve
nodes + metadata
Use Stacksona after retrieval and before final synthesis when the answer depends on restricted sources, missing citations, or high-impact recommendations.
Governance object: retrieved nodes + citation/source policy.
nodes + metadata
source risk
citation policy
source approval
with constraints
auditable output
The useful integration point is the last safe moment before an external action, privileged read, or customer-visible response occurs.
Use these steps as the first implementation pass. Start with one high-risk action, verify the reviewer workflow, then expand coverage.
For Node.js or TypeScript guard services, start with the live SDK. For Python runtimes, call the same guard through your backend or a small HTTP wrapper.
npm i @stacksona/sdk
View SDK on npm
Keep the payload compact enough for a reviewer to decide quickly, but specific enough to explain exactly what the agent wants to do.
| Field | What to include |
|---|---|
| agent | Stable name for the agent, crew, graph, or workflow that is asking for approval. |
| action | Human-readable verb such as send_email, issue_refund, or execute_tool. |
| risk | Use low, medium, or high so reviewers can triage quickly. |
| subject | The customer, ticket, repository, account, or data source affected by the action. |
| context | Small, reviewable facts: proposed arguments, policy signals, retrieved sources, role, task id, and links. |
def governed_query(query, retriever, synthesizer):
nodes = retriever.retrieve(query)
risk = classify_retrieval_risk(nodes)
decision = gate_request({
"agent": "research-assistant",
"action": "synthesize_answer",
"risk": risk,
"subject": query,
"context": {
"source_ids": [node.node_id for node in nodes],
"source_titles": [node.metadata.get("title") for node in nodes],
"policy_labels": collect_policy_labels(nodes),
},
})
if decision["status"] != "approved":
return "Answer paused for source review."
return synthesizer.synthesize(query, nodes, citation_required=True)
Treat this as the shape of the guard. Replace gate_request, stacksona.gate.request, or run_tool with the SDK/API calls used in your runtime.
Post-retrieval, pre-synthesis, or before sending answers to external channels.
Source metadata, sensitivity labels, citation status, and intended audience.
Do not wait until after final answer generation to discover restricted-source use.