Menu
← Research

Field Notes

Put the policy at the tool call.

ActaClad

A requested action is not permission to execute. AgentGuard tool permissions can allow a tool, make it read-only, require approval or block it. The approval state belongs beside the tool action, not inside the model prompt.

FIGURE 01AgentGuard tool-permission model

A tool request is not permission.

Agent requests a tool action
Policy boundaryEvaluate permission before execution.
  • AllowPermit the tool action.
  • Read-onlyRestrict to reading.
  • Require approvalHold for a human decision.
  • BlockPrevent the action.
The permission decision belongs at the tool boundary. A model prompt alone is not an execution permission.
Read as Markdown ↗All research →