API Reference
EffectClass
All six effect classes, fail-closed defaults, block-and-gate, and sandbox behavior.
Effect classes decide how crashes, retries, and sandbox mode treat a tool. Unknown classifications fail closed.
Values
| Class | Retry on crash? | Notes |
|---|---|---|
PURE | Yes (recompute) | No side effects |
READ_ONLY | Yes | Reads only |
IDEMPOTENT_WRITE | Yes (with idempotency key) | Safe retries |
NON_IDEMPOTENT_WRITE | No — block-and-gate | Emails, charges, deploys |
AGENT_SPAWN | Policy / sandbox sensitive | Spawning agents |
SENSITIVE | Policy / sandbox sensitive | Secrets / PII-class ops |
Block-and-gate
If a NON_IDEMPOTENT_WRITE is interrupted, resume must not blindly re-fire the tool. The runtime enters a gated state until policy or a human resolves it.
Sandbox
Sandbox mode rejects dangerous classes before side effects, including:
NON_IDEMPOTENT_WRITEAGENT_SPAWNSENSITIVE
Use it for demos and CI. See Sandbox demo.
Language bindings
- Go:
trajir/effects - Python:
trajectory_ir.effects.EffectClass
Do not invent APIs like SecurityLevel.HIGH_RISK — they are not part of Trajectory IR.

