Jev in production › Agent guardrails and approvals
Jev answers one question per safety rule to allow, block, or ask before each tool call the Pi coding agent executes, with safety behavior benchmarked using DSPy.
An auto-mode safety monitor for the Pi coding agent. Every tool call Pi is about to run is judged by a program that asks a System One classifier one question per rule, then decides allow, block, or ask in code. The program is written and benchmarked in DSPy 3.4 against TypeSafe's Jev (jevauto/), then exported to a TypeScript Pi extension (pi-extension/, package pi-system-one-auto) that calls lunaroute/djev by default.
The rules come from autoprompt.md, a monolithic LLM classifier prompt. Following the Jev skill, the prompt is decomposed rather than sent whole:
For the project's own README, linking back here: