Skip to contents

Buffers provider chunks and releases text only after scan_stream() has made a final decision over the complete response. This conservative contract prevents split payloads from reaching the consumer and makes cancellation explicit. It trades token-by-token display for a release guarantee; callers must send raw provider chunks only to $push().

Usage

stream_guard(
  emit,
  cancel = NULL,
  policy = "enterprise_default",
  reviewer = NULL,
  checks = "rules",
  overlap = 200L,
  redaction = NULL,
  scanners = scanner_options(),
  show_tokens = FALSE,
  show_stats = FALSE
)

Arguments

emit

Function receiving the final cleaned text after an allow/redact decision.

cancel

Optional function called when the guard blocks or is cancelled.

policy

A shieldr_policy or built-in policy name.

reviewer

Optional reviewer function or object with $chat().

checks

One of "rules", "nlp", "llm", or "both".

overlap

Number of trailing characters from prior output to include when scanning the next chunk.

redaction

Optional redaction strategy from redaction_strategy().

scanners

Optional scanner configuration from scanner_options().

show_tokens

Whether to attach token counts when ellmer is available.

show_stats

Show construction time and available usage metrics.

Value

A shieldr_stream_guard environment with $push(chunk), $finish(), $cancel(), and $status() methods. Each method accepts show_stats.

Examples

released <- character()
guard <- stream_guard(function(text) released <<- c(released, text))
guard$push("Contact ")
guard$push("a@example.com")
result <- guard$finish()