Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Tool calls: validate intent and arguments before an external effect

Last updated: 5 Oct 20268 min read
tutorial
IntermediateBy AITrove Editorial

A tool schema constrains argument shape, but it does not grant authority. The executor must check the signed-in user's permission, resource ownership, allowed operation, idempotency key, and expected side effect. Separate read tools from write tools and use confirmation where the action's risk calls for it. Tool results are lower-trust data on return, even if they came from an authorized API. A prompt can tell the model to ask for a tool only when needed, but enforcement must live outside the prompt in application code.

Decision in practice

A billing assistant may read invoice INV-2837 and suggest a refund. The customer says to reverse the charge, but the active agent identity has only read permission. The model proposes issue_refund with invoice_id and amount. The executor rejects the call before sending it because the user lacks refund authority. For an authorized finance operator, it also verifies the invoice belongs to the intended account, the amount is within the remaining refundable balance, and an idempotency key is present. A tool result that says approved cannot override the local authorization check.

Output
Proposed action: issue_refund(invoice_id=INV-2837, amount=47.00).
Executor checks: actor role, account match, refundable balance, idempotency key.
Read-only actor: deny without sending the action.
Authorized actor: execute once; record receipt and reconcile outcome.

Performance and operating cost

Authorization checks add a database or policy lookup per proposed effect, but the cost is bounded and necessary. Retries need a stable idempotency key or an uncertain network response can create duplicate effects. Log the decision and receipt without exposing payment secrets. Measure rejected unauthorized calls, duplicate attempts, and requests needing human review. A model's explanation of why a call is allowed is useful context for an operator, never a replacement for the executor's policy decision.

Common Mistakes

  • Do not mistake a valid tool schema for permission.
  • Do not retry an uncertain write with a new effect identity.
  • Do not let a tool result rewrite the user's authority.

Connected lessons

Next decision

Check whether the right facts reached the workflow and whether the result is safe at its destination.

Continue with: Tool catalogs: describe eligibility, inputs, and effects.

Continue with: Request risk routing: classify the action before choosing a response.

Continue with: Browser agents: separate observed state from intended action.

Continue with: Specialist task packets: scope evidence and authority explicitly.

Continue with: Meeting actions: verify owner, task, and due date.

Continue with: Infrastructure prompts: bind scope, owner, and environment.

Continue with: Recurring prompts: renew authority for sensitive actions.

Continue with: Support prompts: verify entitlement and requester authority.

Continue with: Invoice prompts: route exceptions before approval.

Continue with: Backfill prompts: bound batches and make retries idempotent.

prompt engineering
tutorial
Storage details