Learning on Web Dev Open is free for all.

AI-Native Products > Structure, tools and the agent you did not needA tool is a function call with manners
Phase 08Structure, tools and the agent you did not need400 of 434

A tool is a function call with manners

The model does not run anything. It emits a name and arguments, you decide whether to honour them, and that boundary is your security model.

Concept13 minAI pair

Tool use is a structured output with a convention attached. You describe available functions with a schema; the model returns a request to call one with arguments; your code validates and executes it if it chooses to; the result goes back in as another message and the model continues. At no point does the model execute anything or hold any privilege.

That means every authorisation decision is yours and belongs in ordinary code: the same checks you would apply to a request from an untrusted client, because that is exactly what a tool call is. Arguments are attacker-influenceable input. Validate types, bound ranges, check the current user actually owns the record, and never construct a query by interpolating what came back.

The failure everyone makes once is putting the rule in the prompt: telling the model it may only refund up to fifty pounds. That is a suggestion to a text generator, not a control. The control is the fifty-pound check in the function.

You should now be able to

  • Describe the full round trip of a tool call
  • Identify who is responsible for authorisation
Ask the community

Loading…