Tool controls
Allow or deny tool calls by tool name, declared annotations, wire type or argument values, independently of what data they carry.
Where it is configured
Tool controls are a Policy Engine feature. There is no app setting or Configure tab for them, so nothing freezes when you use them. Open the Tool Controls card in Policy Engine > LLM Gateway. Edits join the shared draft and take effect once you review and publish a revision.
Sections
Tool calls applies on assistants, bedrock, chat, copilot, embeddings, rerank, responses, sdk_check, stt, text, tts and vertex.
Every tool call in a request is judged on its own, but one denied call rejects the whole request. The engine never strips a single call. Per-call verdicts stay visible in attribution.
Tool rule settings
Risk and tags are not computed by the gateway, so the quick rule does not offer them. Use Add configuration for result-field conditions on the response stage or combinations the quick rule cannot express.
Scenarios
- Block destructive tools for most people. Deny calls whose trait is Destructive for Everyone, then allow them at a higher priority for one Smart group.
- Block one risky argument value. Deny
create_repositorywhenvisibilityispublic:
runs on requestpriority 950
- Pattern rules. Deny every
delete_*tool for one Application or Requested model.
To scan tool arguments for secrets or PII instead, add a data rule with Scan tool-call arguments on Data & Adversarial Risks. Only Monitor and Block apply there, because redaction cannot preserve a call.
Scoping and precedence
- Applies to: Everyone, People, Smart group, Application, App tag, Requested model, Provider, API surface, Environment, Tool, Source network, or Except....
- Highest priority wins for each call.
Test before you publish
The LLM Gateway workspace in the Policy Engine has tools around the cards that help when you build tool rules:
- What applies to one request (Describe a request): enter a person, Smart groups, application, requested model, API surface, environment, provider credential, source IP and detections. Each card shows the winning value, the configuration that decided it and why. Values that depend on a field you left empty are tagged conditional. Nothing is saved. Test with the engine compares the answer with the engine's simulator, and Open full simulator opens the simulator.
- Review changes: validates the shared draft and replays it over sampled recorded traffic, with global counters (blocked, redacted, rerouted, model rejected, rate-limited).
- History: every published revision with time, actor, checksum, View source and Rollback (rollback republishes as a new revision).
- Advanced policies: policies the cards cannot represent are listed below the cards. Advanced workspace opens the QuilrQL source editor with drafts, suggested policies (for example deny tool access), diagnostics, simulation and historical try.
Related
- Security guardrails - scan tool-call arguments for sensitive data.
- Gateway access and allowed models
- Policy Engine overview