# The send gate

> One check between an agent's draft and the send. It answers allow, redact, review or block, names the rule that decided it, and takes a context that says who the message is for. It is Overwing Guardrails with the prebuilt `outbound-message` rule set.

## The call

```
curl -X POST https://overwing.ai/api/v1/evaluate -H "Content-Type: application/json" \
  -d '{"input": "<the message>", "rule_set": "outbound-message",
       "context": {"recipient": "customer", "channel": "email", "owns_contact_info": false}}'
```

It works with no key, 10 times a day. With a key (`Authorization: Bearer <key>`, free from `POST https://overwing.ai/api/v1/signup`) it is 250 a day. Branch on `recommended_action` in the response.

## The four answers

- **allow.** Nothing in the rules objects. Send it.
- **redact.** It carries personal data this recipient should not get. The answer names the rule; your code removes the detail or sends a fallback. The AI SDK middleware swaps in your fallback on its own.
- **review.** The model was not confident enough to rule either way. Hold the message and show it to a person, with the reasons.
- **block.** A secret, a threat, or something the context does not authorize. Do not send.

When more than one rule fails, the strictest action is the one recommended.

## The rules

| Rule | What it catches | If it fails |
|---|---|---|
| `unauthorized_pii` | Personal data that is not the sender's own, or is not meant for this recipient: emails, phone numbers, addresses, ID and account numbers. | redact |
| `confidential_leak` | Credentials, internal system details, unreleased plans, non-public pricing, or another person's private matters that the context does not authorize sharing. | block |
| `toxicity` | Hostile, hateful, threatening or abusive language toward the recipient or anyone mentioned. | block |
| `self_harm` | Encouragement of, or instructions for, self-harm or suicide. | block |
| `sexual_content` | Explicit sexual content, judged against the recipient and the channel. | block |
| `severity` | The overall harm if the message reached its recipient as written, on a five-level scale. | block |

Each rule is a plain-language question answered by TypeSafe's Jev model with a typed answer and a calibrated confidence. Low confidence becomes review. An organization can add its own rules and rule sets. A model's judgment is a signal, not a guarantee.

## Where it goes

- Vercel AI SDK: `overwingGuardrail({ ruleSet: "outbound-message", context })` from `overwing/ai-sdk` (npm `overwing`)
- OpenAI Agents SDK: input and output guardrails, JavaScript (npm `overwing`) and Python (PyPI `overwing[agents]`)
- LangChain: `overwing_guard` and a callback handler (PyPI `overwing[langchain]`)
- MCP: the `evaluate` tool on https://overwing.ai/mcp
- Plain HTTP, with idempotency keys and batches

## Starting

Run it in shadow first: call the gate, record the answer, and send anyway, for about 14 days. Send `"store": false` and the message and its context are not kept. Without a key the text is never stored.

For the first 5 teams Overwing writes the rule set with them at no charge beyond the plan. A person writes to support@overwing.ai.

## Price

One check is one evaluation. Free: free, 250 a day. Starter: $29 a month, 5,000 a day. Growth: $99 a month, 25,000 a day. Scale: $299 a month, 100,000 a day. Or $0.002 a check in USDC over x402 with no account, at `POST https://overwing.ai/api/x402/evaluate`. Live prices: https://overwing.ai/api/v1/plans.

Gating actions rather than messages is Overwing Tower: https://overwing.ai/products/tower. Page: https://overwing.ai/gate. Guide: https://overwing.ai/llms.txt.
