# Put the policy at the tool call.

Field Notes · ActaClad



A requested action is not permission to execute. AgentGuard tool permissions can allow a tool, make it read-only, require approval or block it. The approval state belongs beside the tool action, not inside the model prompt.

### Figure — A tool request is not permission.

AgentGuard tool-permission model

Agent requests a tool action → Policy boundary (Evaluate permission before execution.)

Outcomes:
- Allow (Permit the tool action.)
- Read-only (Restrict to reading.)
- Require approval (Hold for a human decision.)
- Block (Prevent the action.)

The permission decision belongs at the tool boundary. A model prompt alone is not an execution permission.

