Skip to main content

Tool visibility

Choose which of a server's tools AI agents can call. Disabled tools are hidden from every client, so agents never see them in their tool list.

Configure it on the server​

Go toQuilrAI consoleSettingsAI GatewayMCP Gatewayserver cardConfigureTools

You can also open Overall analytics > Settings, select one server and choose Tools. The section subtitle shows how many tools are exposed, for example 12 of 15 exposed.

Tool groups​

Tools are grouped by what they do to the upstream system.

GroupWhat the tools do
Read-only toolsOnly read data.
Write toolsCreate or change data.
Destructive toolsDelete data or make irreversible changes.

The Exposed to agents bar at the top shows how many tools in each group are enabled, for example Write 3 / 4.

Per-tool controls​

ColumnWhat it does
ToolName and description. Click View input schema to see the inputs the tool accepts.
CallsHow many calls the tool has received.
EnabledOff hides the tool from every client.
Require confirmationThe user must approve each call before it runs. See Human approval.
Require justificationThe user must type a reason to approve. Only available with confirmation on.

Changes are drafts. Click Save settings in the footer to apply them.

Find a tool​

ControlUse
Search toolsFilter by tool name or description.
All / Read-only / Write / DestructiveShow one group. Each tab shows its tool count.

Refresh the tool list​

Click Refresh tools to fetch the server's current tool list. If the list is empty, the gateway hasn't fetched the tools yet; refresh, or connect OAuth first if the server needs it.

The Upstream tool changes card above the tool list watches for tools the server adds, removes or changes. See Tool change watch.

Per group and per user​

To enable a tool, or require confirmation, only for some people, add a rule in Group and user rules. A rule can set each tool's Enabled, Confirmation and Justification to Inherit, On or Off for one smart group or one user.

Going further with the Policy Engine​

When the Policy Engine is on for the MCP Gateway, the Tools section turns read-only and shows Controlled by Policy Engine; values saved through Edit anyway apply only if the Policy Engine is disabled (see What happens to classic settings). Tool availability then comes from two cards in Govern > Policy Engine > MCP Gateway:

CardStageWhat a deny does
Discovery Visibility2, DiscoveryRemoves the tool from the list the agent is offered.
Invocation3, RequestRefuses the call if the agent calls the tool anyway.

Use both. An agent that cached an earlier tool list can still attempt a call, so hiding a tool alone is not enough. Edits join a shared draft and apply once you publish a revision.

Scenarios the cards support that the Tools switches cannot:

  • Hide tools by what they do, across servers. Match the tool's read_only, destructive, idempotent or open_world annotations, its tags or its risk, instead of switching tools off one by one.
  • Hide tools from some callers only. Combine a tool condition with smart groups, user email or agent name, for example hide write tools from one AI client.
  • Hide resources and prompts. Besides tools, Discovery Visibility can deny MCP resources (by URI, template, name or MIME type) and prompts (by name), which have no switch in server settings.
hide_destructive_github_tools

priority 850

Rule 1 - runs on discovery
WhenMCP nameisGitHub
andTool is destructiveistrue
Then
Tool call accessdeny
Rule 2 - runs on request
WhenMCP nameisGitHub
andTool is destructiveistrue
Then
Tool call accessdeny