Guide

Review an Agent’s Tools and Data Access

Inspect each connected tool for its identity, data scope, allowed operations, side effects, returned information, and failure behavior.

By AgentShelfUpdated September 28, 2026

Agentshelf Knowledge Guide

Review an agent’s tools one operation at a time: confirm what each can read or change, which identity it uses, which records it can reach, and what evidence shows that limits work. A workflow-level instruction does not replace access checks in the connected system.

Review one equipment request

A facilities coordinator asks an agent to check a replacement request against the approved equipment catalog and current stock list, then prepare draft text for review. The agent may read the assigned ticket, approved catalog, and stock for the requested item at the assigned site. It cannot submit a purchase or update inventory.

In this fictional test, the lookup tools run as a dedicated facilities service account. The connected systems permit the assigned ticket and item/site stock lookup, while denying an unrelated ticket and stock at another site without returning their contents. An unapproved catalog item is excluded; purchase submission and inventory updates are unavailable. The agent returns draft text to the coordinator rather than writing a requisition to another system. The completed review is:

Scroll horizontally to see all columns.

OperationIdentity and scopeAccess and side effectReturn and failure response
Ticket lookupFacilities service account; assigned request only.Read is allowed; an unrelated-ticket lookup is denied by the ticket system.Return assigned-request fields only; the denial returns no record details. The operator handles a failed lookup.
Catalog lookupFacilities service account; approved items and requirements.Read is allowed; no catalog-edit operation is available. An unapproved item is excluded.Return the approved item and requirements. If the source is unavailable, do not infer its contents; route the lookup failure to the operator.
Stock lookupFacilities service account; requested item at the assigned site.Read is allowed; another-site lookup is denied without revealing its contents.Return availability for the assigned site only. If the lookup fails, leave stock unverified and route it to the operator.
Requisition draftAgent workflow returns text to the facilities coordinator; no connected-system identity is used for this output.Preparing draft text is allowed; purchase submission is unavailable.Return a draft for review. If a required lookup failed, mark it incomplete and do not submit a purchase.
Inventory updateNo identity or update operation is granted.Blocked; it would change the inventory record.No inventory data changes. If an update path is present in the configured system, hold the pilot until its denial is verified.

Decision: Allow a bounded pilot for the listed read and draft operations; an operator handles lookup failures.

This review checks the actual tools and data paths for the example. It does not imply that a named platform supplies these controls; confirm each operation in the configured system.

A task at the center of four connected categories: knowledge, skills, tools, and connections

Knowledge, procedures, tools, and connections play different roles in one task.

Use one row for each tool operation

Scroll horizontally to see all columns.

CheckQuestions to answer
Owner and purposeWho owns the source or service? Which step of the job needs this operation?
IdentityDoes the call run as a user, agent, service, or shared account? Whose access does that identity represent, and can it be revoked?
ScopeWhich records, folders, fields, or tenants are reachable? Can the system constrain the request to the relevant case?
Operation and side effectIs the tool reading, searching, creating a draft, submitting, updating, deleting, or sending? What downstream effect follows?
Data returned or sentWhich fields come back to the agent, and what information leaves for the connected service? Can unnecessary fields be omitted?
Validation and failureHow are inputs checked? What happens on denial, timeout, malformed output, or duplicate request? Is it safe to retry?
Evidence and reviewWhich allow and deny tests show the real behavior? Who can see failures and investigate them?

Do not treat a service’s label as its full permission scope. A tool called “lookup” might expose broad search results; a tool called “draft” might save data in a shared location. Inspect its actual arguments, return values, side effects, and account permissions.

Test both the permitted and blocked paths

For the equipment example, test an assigned ticket, an unrelated ticket, permitted and blocked item/site stock lookups, a catalog item that is not approved, a request to submit a purchase, and a timeout followed by a retry. Confirm which system enforces each decision. The agent should receive only the intended item and should not gain additional access because a person asked it to ignore the boundary.

Retest when the connector, account, scope filter, operation, or agent job changes. Separate this per-tool review from the audience and workspace review in operating boundaries, and pair it with the security review checklist. For the broader distinction among approved information, procedures, tools, and connections, see knowledge, skills, tools, and connections.

Your privacy choices

We use optional assistant personalization, analytics, and advertising technologies only when you allow them. Necessary site functions remain active. Cookie Policy