Skip to main content

Tool Controls

V2 console

This card lives in Policy Engine > LLM Gateway at web.quilr.ai/policy. Edits join the shared draft and take effect once you review and publish a revision.

Allow or deny tool calls by tool name, declared annotations, wire type or argument values, independently of what data they carry.

Tool Controls card expanded with the per-call banner, a Deny rule for delete_* tools, and the Argument & result protection section

Sections​

SectionWhat it doesAdd button
Tool callsPer-call allow or deny rules.Add tool rule
Argument & result protectionLists the Data & Adversarial Risks rules scoped to the tool boundary. Edit them on that card.Open Data & Adversarial Risks

Tool calls applies on assistants, bedrock, chat, copilot, embeddings, rerank, responses, sdk_check, stt, text, tts and vertex.

Every tool call in a request is judged on its own, but one denied call rejects the whole request. The engine never strips a single call. Per-call verdicts stay visible in attribution.

Tool rule settings​

SettingOptionsDefaultNotes
ToolTool names or patterns (delete_*), or Any toolEmptyNames and patterns are alternatives. Leave empty or tick Any tool to judge every call by traits or arguments.
By traitDestructive, Open world, Not read-only, Read-only, IdempotentNoneDeclared MCP-style annotations read from the call. Match any trait (default) or all traits.
Tool typeWire type, for example functionEmptyPatterns allowed.
When argumentsArgument path + is, is not, one of, contains, starts with, ends with, matches *wildcard*, exists, is emptyNonePaths are suggested per tool from observed calls; nested paths like options.visibility work. Text conditions ignore case. Values are never stored. Match all (default) or any.
DecisionAllow, DenyDenyA deny rejects the whole request that carries the call.
SeverityNot set, Very low, Low, Medium, High, Critical, Very criticalNot setReported only.

Risk and tags are not computed by the gateway, so the quick rule does not offer them. Use Add configuration for result-field conditions on the response stage or combinations the quick rule cannot express.

Example​

deny_public_repository_creationrequest

runs on requestpriority 950

WhenTool nameiscreate_repository
andTool arguments . visibilityispublic
Then
Tool call accessdeny
Risk levelhigh

To scan tool arguments for secrets or PII instead, add a data rule with Scan tool-call arguments on Data & Adversarial Risks. Only Monitor and Block apply there, because redaction cannot preserve a call.

Scoping and precedence​

  • Applies to: Everyone, People, Smart group, Application, App tag, Requested model, Provider, API surface, Environment, Tool, Source network, or Except....
  • Highest priority wins for each call.

Legacy app setting​

None. Tool Controls is a policy-only control with no equivalent app settings section.