Tool Controls
This card lives in Policy Engine > LLM Gateway at web.quilr.ai/policy. Edits join the shared draft and take effect once you review and publish a revision.
Allow or deny tool calls by tool name, declared annotations, wire type or argument values, independently of what data they carry.

Sections
Tool calls applies on assistants, bedrock, chat, copilot, embeddings, rerank, responses, sdk_check, stt, text, tts and vertex.
Every tool call in a request is judged on its own, but one denied call rejects the whole request. The engine never strips a single call. Per-call verdicts stay visible in attribution.
Tool rule settings
Risk and tags are not computed by the gateway, so the quick rule does not offer them. Use Add configuration for result-field conditions on the response stage or combinations the quick rule cannot express.
Example
runs on requestpriority 950
To scan tool arguments for secrets or PII instead, add a data rule with Scan tool-call arguments on Data & Adversarial Risks. Only Monitor and Block apply there, because redaction cannot preserve a call.
Scoping and precedence
- Applies to: Everyone, People, Smart group, Application, App tag, Requested model, Provider, API surface, Environment, Tool, Source network, or Except....
- Highest priority wins for each call.
Legacy app setting
None. Tool Controls is a policy-only control with no equivalent app settings section.