Hooks are the part of Digitorn that turns a working agent into a production-ready one, and you add them without writing any code. This piece walks through the four guardrails that actually ship in our builtins today. Each one is a small rule: when this happens, if this is true, do this.
There are four moments a hook can attach to. Turn start runs before the agent sees the next user message. Tool start and tool end wrap each tool call. Turn end runs after the agent has produced its response. The four guardrails below hang off tool start, tool end, and turn end.
1. Lint after every write
The single guardrail that comes closest to mandatory for a coding agent. After any tool call that writes a file, run the linter, and feed the diagnostics back into the next turn. The agent self-corrects on the next pass without you writing the loop.
The load-bearing detail is that the diagnostics get merged into the tool's own result, so the agent sees "wrote 42 lines, 2 errors" in the same breath as the success status. Without that, the agent thinks the write succeeded and moves on. With it, it reaches for the fix automatically. The diagnostics can also be pushed to the preview so a connected editor renders them inline.
2. Hard ceiling on a specific tool
The simplest guard for a third-party API is a hard ceiling. Past N calls to that tool in a session, the guardrail fires and the agent receives a refusal it can react to, rather than pounding the API. The running count is tracked for you; you just set the tool and the threshold. The agent reads the error and typically reframes its plan.
3. Global cap on runaway loops, plus an ops alert
The horror story everyone has heard: an agent loop runs unattended, hits some weird state, and racks up cost before anyone notices. The simplest hard guard is an unconditional tool-call ceiling. Past N calls in a session, block the next call and notify your team, in that order. Tool-call count is a coarse but reliable proxy for cost: every call has a non-zero LLM cost, so capping calls caps the bill. (Direct token-cost ceilings are on the roadmap.)
4. Notify on tool failure
The fastest way to learn an agent is failing on a specific tool is to surface the failure in real time. Whenever a tool returns an error, post the event, carrying the failing tool's name and the exact error, to your logs and any observability sink you've connected. It's the lightest possible diagnostic guardrail, and a free first line of defence against silent failures. If you also want the agent to react to the failure (retry on a different endpoint, fall back to a cheaper tool), a hook can route the failed call into a second tool instead of just reporting it.
Stacking the four
The guardrails compose. A typical production-leaning agent runs all four at once: lint on writes, a per-tool cap on the risky API, a global runaway ceiling with an ops alert, and failure notifications. Four rules, four production behaviours, and you can read them at a glance in the agent's settings.
What's on the roadmap
The system is moving forward. A few guardrails we want to ship that need runtime work first, in case you're scoping a longer-term plan:
- Goal injection at turn start. Pin the user's original goal at the top of every turn so the agent can't drift after compaction.
- LLM-driven transformations in hooks. Auto-summarise large tool results, classify intent before routing, run a fact-check pass after a write.
- Token-cost ceilings. Hard-cap an agent at a set spend per session, once per-session cost is available to a guardrail condition.
When these land they'll appear here. We didn't want this article to be a wishlist: the four above are the ones you can ship today.
Try it
Add any of the four guardrails to an agent in Studio, adjust the tool names and thresholds for your case, and run it. Production agents in Digitorn's own catalog run the same shapes, applied for real, not as a toy example.
Further reading
- Why you build agents in a workspace instead of writing code: Why you shouldn't write your agents in code
- The cost-routing patterns hooks pair with: How we cut our coding agent's bill by 60%
- The full coordinator-plus-specialists architecture: How to build your own Claude Code
- The breadth of apps the system supports: 10 apps you can build in Studio
One post a fortnight, in your inbox.
Engineering notes from the Digitorn team. No marketing, no launch announcements, no "10 prompts that will change your life". Just the things we write that we'd want to read.
We build the open-source AI agent runtime that runs on your own machine. YAML over Python, multi-agent by default, marketplace for sharing.
Keep reading
Ship your first AI agent in 5 minutes.
Open-source. Self-hosted. YAML-first. Bring your own LLM keys, agents run on your machine.
