Skip to content
Rota Nacional

Guides ·

How to constrain an AI agent's tools

Separate lookup, proposal and execution. Give each action limits that prompts cannot expand.

1. Inventory available actions. For every tool, record the data it reads, the effect it produces and its authorized users. Searches need mandatory project filters; writes need specific resource targets. Remove generic execution tools when the task only requires lookup.

2. Separate proposals from effects. An agent may prepare a message or change without receiving permission to send or apply it. The application checks contextual authorization and enforces recipient, volume and expiry limits. A sentence inside a document must never grant access.

3. Minimize tool responses. Return only fields required by the task and process them before inference. Avoid returning full customer records to answer a status question. Apply the same discipline to attachments, retrieved context and error messages.

4. Test useful refusals. Include a document requesting another project's data, a tool returning extra fields and an attempt to repeat a write. The system should prevent unauthorized effects, explain the limit and let the task continue through an authorized path.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free