Laya Guard

Check every agent tool call before it runs

Check an agent’s tool call before it runs: allow, ask or block. Send the proposed call and what the user asked for; get a verdict with the reasons and nine calibrated scores in one pass. On your Laya Studio key, at $0.20 per 1k checks.

The agent proposes

db.drop_table({ table: "users" })

The user asked

List the tables in the staging database

Block

P(unsafe) 0.960

  • Destructive0.999
  • Arguments match the request0.214
  • Injected by a tool result0.031
  • Data exfiltration0.021

One check, nine scores, ~15 ms of GPU time.

~15 ms
per check on an RTX 4090 (p95 ~23 ms)
9
calibrated scores per check, one pass
0.855
AUROC on the R-Judge test half
$0.20
per 1,000 checks

How it fits

One call in your pre-tool-call hook

The agent proposes a tool call, your hook sends it to the guard, and only an allow runs without a human. Ask goes to the user; block never runs.

  • Agent frameworks. call POST /v1/guard from the hook that runs before every tool call.
  • MCP clients and gateways. use the guard_check and guard_batch tools on https://api.laya.studio/mcp, with the same key.
  • Code-mode sandboxes. check every call a generated script makes in one guard_batch request.
check.shbash
curl https://api.laya.studio/v1/guard \
  -H "Authorization: Bearer $LAYA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "action": { "tool": "db.drop_table", "args": { "table": "users" } },
    "intent": "List the tables in the staging database",
    "context": "Database agent. Environment: production."
  }'

What it answers

Nine questions about every call, in one pass

safeProbability the call is safe to run now.
violationnone, policy_violation, scope_violation, injection, goal_drift or corrigibility.
severitynone < low < medium < high.
destructiveDeletes, overwrites or irreversibly changes data.
exfiltrationSends private data, secrets or another tenant’s data where it should not go.
injectedDriven by instructions from a tool result or document, not the user (prompt injection).
approval_policyauto_approve, require_human or reject.
blast_radiusread-only < local or reversible write < production-mutating or external side effect.
args_groundedThe arguments are supported by what the user asked (no invented ids, amounts or recipients).

FAQ

Laya Guard, answered

What is Laya Guard?
A check you run on an AI agent’s tool call before it executes. You send the action (for example db.drop_table(users) or {tool, args}) and what the user asked for; it returns a verdict (allow, ask or block), the reasons, and calibrated scores for nine questions, from one forward pass of a small model.
Which model runs it?
Our own guard model, a DeBERTa-v3-base encoder (184M parameters) with nine heads, trained on labelled agent actions. It is not the Laya decision model: a dedicated classifier matched Laya’s accuracy on this task at half the latency. It runs on the same GPUs as Laya Decisions, in Switzerland first.
How accurate is it?
On the held-out test half of R-Judge, a public benchmark of agent safety trajectories (304 trajectories), it scores an AUROC of 0.855, against 0.824 for saroku-guard, an open guard model of the same size. The difference is not yet statistically significant, so read it as on par with or better than that baseline, not as a ranking. Measure it on your own traffic before you rely on it.
Does it replace my allow-lists and rules?
No. It is one layer. Keep deterministic rules for patterns you already know are bad (blocked commands, allow-listed domains, permission scopes). The guard is for the long tail your rules do not describe: actions that are off-intent, injected by a document, or riskier than the request justifies.
What does it cost?
$0.20 per 1k checks: 5,602 credits per check, from the same balance and plans as Laya Decisions. One check is one tool call judged on all nine questions. Swiss-only checks cost 15% more, like decisions. Failed checks are free.
Is this the same as mcp-guard.ai?
Same model, same price, same GPUs. mcp-guard.ai sells it on its own; on Laya Studio it shares one account, key and balance with Laya Decisions, so you can guard an agent and answer its typed questions on one bill.
Do you store my tool calls?
No. Request payloads (the action, intent, context) are processed in memory and not stored. We keep request metadata (ids, verdict, latency, credits) for 30 days for billing and debugging.

Guard your first agent today

One key, one balance for Laya Decisions and Laya Guard. $0.20 per 1k checks; failed checks are free.