direction on every call (input before
the model, output after). Defaults to input if omitted.
Coverage
Ask —
status is advisory: nothing prompts anyone unless your code does.
Use it when the model call lives in your Python code and the policy decision
needs context only the application has — the authenticated user, the tenant, the
retrieved document. Not as your only defence when you need a guarantee a
developer cannot bypass by forgetting a branch; that is a
gateway collector.
⚠️ TrustGuard returns the verdict, your code enforces it. Code that logs a
block and calls the model anyway is monitoring; ignoring transformed_payload
forwards unmasked data. Tool-level coverage means calling evaluate with
protocol: "mcp" around your tool dispatch.
Limits. Coverage is per call site. If that worries you, use
Python middleware.
Full comparison: Coverage.