Review an agent’s tools one operation at a time: confirm what each can read or change, which identity it uses, which records it can reach, and what evidence shows that limits work. A workflow-level instruction does not replace access checks in the connected system.
Review one equipment request
A facilities coordinator asks an agent to check a replacement request against the approved equipment catalog and current stock list, then prepare draft text for review. The agent may read the assigned ticket, approved catalog, and stock for the requested item at the assigned site. It cannot submit a purchase or update inventory.
In this fictional test, the lookup tools run as a dedicated facilities service account. The connected systems permit the assigned ticket and item/site stock lookup, while denying an unrelated ticket and stock at another site without returning their contents. An unapproved catalog item is excluded; purchase submission and inventory updates are unavailable. The agent returns draft text to the coordinator rather than writing a requisition to another system. The completed review is:
Scroll horizontally to see all columns.
| Operation | Identity and scope | Access and side effect | Return and failure response |
|---|---|---|---|
| Ticket lookup | Facilities service account; assigned request only. | Read is allowed; an unrelated-ticket lookup is denied by the ticket system. | Return assigned-request fields only; the denial returns no record details. The operator handles a failed lookup. |
| Catalog lookup | Facilities service account; approved items and requirements. | Read is allowed; no catalog-edit operation is available. An unapproved item is excluded. | Return the approved item and requirements. If the source is unavailable, do not infer its contents; route the lookup failure to the operator. |
| Stock lookup | Facilities service account; requested item at the assigned site. | Read is allowed; another-site lookup is denied without revealing its contents. | Return availability for the assigned site only. If the lookup fails, leave stock unverified and route it to the operator. |
| Requisition draft | Agent workflow returns text to the facilities coordinator; no connected-system identity is used for this output. | Preparing draft text is allowed; purchase submission is unavailable. | Return a draft for review. If a required lookup failed, mark it incomplete and do not submit a purchase. |
| Inventory update | No identity or update operation is granted. | Blocked; it would change the inventory record. | No inventory data changes. If an update path is present in the configured system, hold the pilot until its denial is verified. |
Decision: Allow a bounded pilot for the listed read and draft operations; an operator handles lookup failures.
This review checks the actual tools and data paths for the example. It does not imply that a named platform supplies these controls; confirm each operation in the configured system.
Knowledge, procedures, tools, and connections play different roles in one task.
Use one row for each tool operation
Scroll horizontally to see all columns.
| Check | Questions to answer |
|---|---|
| Owner and purpose | Who owns the source or service? Which step of the job needs this operation? |
| Identity | Does the call run as a user, agent, service, or shared account? Whose access does that identity represent, and can it be revoked? |
| Scope | Which records, folders, fields, or tenants are reachable? Can the system constrain the request to the relevant case? |
| Operation and side effect | Is the tool reading, searching, creating a draft, submitting, updating, deleting, or sending? What downstream effect follows? |
| Data returned or sent | Which fields come back to the agent, and what information leaves for the connected service? Can unnecessary fields be omitted? |
| Validation and failure | How are inputs checked? What happens on denial, timeout, malformed output, or duplicate request? Is it safe to retry? |
| Evidence and review | Which allow and deny tests show the real behavior? Who can see failures and investigate them? |
Do not treat a service’s label as its full permission scope. A tool called “lookup” might expose broad search results; a tool called “draft” might save data in a shared location. Inspect its actual arguments, return values, side effects, and account permissions.
Test both the permitted and blocked paths
For the equipment example, test an assigned ticket, an unrelated ticket, permitted and blocked item/site stock lookups, a catalog item that is not approved, a request to submit a purchase, and a timeout followed by a retry. Confirm which system enforces each decision. The agent should receive only the intended item and should not gain additional access because a person asked it to ignore the boundary.
Retest when the connector, account, scope filter, operation, or agent job changes. Separate this per-tool review from the audience and workspace review in operating boundaries, and pair it with the security review checklist. For the broader distinction among approved information, procedures, tools, and connections, see knowledge, skills, tools, and connections.