Skip to content

docs(live): add live agent guardrails guide and Model Armor plugin - #2223

Merged
joefernandez merged 16 commits into
google:mainfrom
allen-stephen:docs-live-guardrails-model-armor
Sep 22, 2026
Merged

joefernandez merged 16 commits into
google:mainfrom
allen-stephen:docs-live-guardrails-model-armor

Conversation

@allen-stephen

Copy link
Copy Markdown
Contributor

Adds comprehensive documentation for live voice agent guardrails and the Model Armor plugin shipped in ADK Python v2.8.0.

  • Adds docs/live/guardrails.md: product-oriented guide covering multi-layered defense (system instructions, platform safety filters, user input validation, agent response validation, and tool execution guardrails).
  • Adds docs/integrations/model-armor.md: guide for ModelArmorPlugin, covering template configuration, single-region requirements, failure handling, and block markers.
  • Updates navigation and cross-references across docs/callbacks/, docs/safety/, docs/plugins/, docs/live/, and mkdocs.yml.

@netlify

netlify Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for adk-docs-preview ready!

Name Link
🔨 Latest commit 77a87fd
🔍 Latest deploy log https://app.netlify.com/projects/adk-docs-preview/deploys/6ab1a115828736000805bba6
😎 Deploy Preview https://deploy-preview-2223--adk-docs-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@kazunori279 kazunori279 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified the two new pages against adk-python 460715b6. Nice to see the live guardrail story written down in one place. Four things I think should be addressed before merge: two code/behavior errors and two gaps around live-specific behavior. Details inline.

I also have a few medium-priority notes (output blocking is best-effort once audio has streamed, the upstream guide's Limitations section isn't carried over, and the function_response description is slightly off) — happy to add those if useful.

Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md
Comment thread docs/integrations/model-armor.md
allen-stephen and others added 2 commits September 14, 2026 09:02
The example used (callback_context, tool_name, tool_args), which matches
neither the agent-level nor the plugin-level tool callback signature, so it
would fail at call time. Use the agent-level form documented by
_SingleBeforeToolCallback: (tool, args, tool_context).

@joefernandez joefernandez left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

RISK REVIEW: Content risk review — 🟡 Medium (score 87). The technical substance checks out: ModelArmorConfig fields and defaults, the ValueError on region mismatch, custom_metadata['model_armor_blocked'], the three live callback sites, the RunConfig transcription defaults, and the Python v2.8.0 tag all match adk-python, and all external links resolve. The remaining issues are wording on a security page: absolute guarantee and latency claims, and one output-screening claim that does not hold for the live audio path. Inline suggestions below.

Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md

@joefernandez joefernandez left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CODE REVIEW: Content risk assessment — score 91 / 🟡 Medium risk. Approve with changes.

Every API-level claim checks out against the released v2.8.0 / v2.9.0 tags of google/adk-python: module paths, ModelArmorConfig fields and defaults, the ValueError conditions, the gcp extra, custom_metadata['model_armor_blocked'], the RunConfig transcription defaults, and safety-settings forwarding into the live connect config. Nothing unreleased is referenced.

The remaining issues are behavioral descriptions of the live callback sites. Two are worth fixing before merge:

  1. docs/callbacks/types-of-callbacks.md:175 — "a block resets the connection" is wrong for the typed-text site and contradicts the new guardrails page.
  2. docs/live/guardrails.md:127 and :195 — the live after_model_callback is never invoked with a finished transcription, so "evaluate the complete turn transcription" is not achievable.

Plus three smaller ones: spoken input is screened after the model has the audio, the callback sees accumulated rather than incremental text, and none of the three examples is wired to an agent.

Comment thread docs/callbacks/types-of-callbacks.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md
Comment thread docs/live/guardrails.md
Comment thread docs/live/guardrails.md
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md

@joefernandez joefernandez left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Content style review — 78/100, 🟡 Medium risk

Both new pages follow the repo templates (integrations front matter, sentence-case headings, Use cases / Prerequisites / Installation / Use with agent), and the nav, plugin-list, and safety-page cross-links all match existing convention. Approve with the changes below.

The one item that should not merge as written is the unqualified security claim in the intro at docs/live/guardrails.md#L7-L10 — house style does not assert that a feature makes something safe or secure.

Also worth a look:

  • Code formatting — all three Python blocks in docs/live/guardrails.md#L101-L176 use 2-space indentation against the repo's 4-space convention, and single-quoted strings where the docs mostly use double.
  • Factual contradiction — docs/callbacks/types-of-callbacks.md#L175 says a block "resets the connection", while docs/live/guardrails.md#L84-L86 says blocking keeps the connection open.
  • Smaller items: an absolute "ensures", four passive constructions, a superlative heading, and two bits of flowery phrasing, all flagged inline.

No instances of "we"/"us", "e.g.", or banned AI phrasing were found.

Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md Outdated
allen-stephen and others added 10 commits September 18, 2026 15:55
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

@joefernandez joefernandez left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the updates. please address a few of these resolved comments (now marked as unresolved)

Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/integrations/model-armor.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated
Comment thread docs/live/guardrails.md Outdated

@joefernandez joefernandez left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this contribution! Approved.

@joefernandez
joefernandez merged commit 3a29a8d into google:main Sep 22, 2026
11 of 12 checks passed
zyantw pushed a commit to zyantw/adk-docs that referenced this pull request Sep 24, 2026
…oogle#2223)

* docs(live): add live agent guardrails guide and Model Armor plugin

* docs(live): fix before_tool_callback signature in guardrails example

The example used (callback_context, tool_name, tool_args), which matches
neither the agent-level nor the plugin-level tool callback signature, so it
would fail at call time. Use the agent-level form documented by
_SingleBeforeToolCallback: (tool, args, tool_context).

* Update docs/live/guardrails.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/integrations/model-armor.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/integrations/model-armor.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/live/guardrails.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/live/guardrails.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/live/guardrails.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/callbacks/types-of-callbacks.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/live/guardrails.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* Update docs/live/guardrails.md

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>

* docs(live): address code and style feedback

---------

Co-authored-by: Joe Fernandez <931947+joefernandez@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants