Code runtime

Stacksona for OpenAI Agents SDK

Wrap each governed function tool so Gate checks the exact selected function arguments before the function executes.

Where Gate goes

Inside the function-tool implementation or a shared execution wrapper used by governed tools.

Keep the platform's normal reasoning and orchestration. Gate only the exact action at the last safe point before execution.

Agent selects functionFunction wrapper checks GateFunction executes or returns control

Start here

  1. 1
    Build the final action.

    Let OpenAI Agents SDK choose the action and produce the arguments it intends to execute.

  2. 2
    Check the exact action with Gate.

    Send tool_name and the final payload immediately before the side effect.

  3. 3
    Follow one of four outcomes.

    Continue, wait, revise, or stop. You do not need the advanced features to get this basic path working.

Minimal setup

Expose the governed wrapper as the callable tool. The wrapper receives the model-selected arguments, validates them, sends the exact proposal to Gate, and only then calls the real implementation.

Handle the decision

OutcomeGate statusWhat OpenAI Agents SDK should do
Continueallow or approvedExecute the exact proposed action. If signed proof is required, validate it first.
Waitpending_reviewStore thread_id and resume that exact review later.
Revisechanges_requestedReturn reviewer feedback to the part of the runtime that can revise the proposal.
Stopreject or rejectedDo not execute. Replan, fall back, or end the action.
Unknown or failed decision = stop.

Fail closed if Gate cannot be reached, returns an unknown state, or required approval proof is missing or invalid.

Platform notes

  • Keep agent reasoning, provider credentials, and function execution in your application.
  • Do not model Gate as a separate optional tool that the agent may skip.
  • Store thread_id in session or job state when review can pause the run.
Advanced: review threads, revisions, proof, and audit

task_id is your grouping ID. thread_id identifies the exact Gate review and should be persisted whenever work can pause.

For changes_requested, revise on the same review thread using the revision event contract. For high-impact actions that require signed proof, validate the returned approval token before execution. Log execution success or failure when you need complete audit evidence.

For long reviews, use the platform's durable continuation mechanism instead of keeping a process, workflow, or runner open.

Advanced runtime patterns Full Gate API Exact decision states