Tool policy combines a default-deny allowlist with per-tool argument schemas,
subject authorization, custom validators, and call, side-effect, and spend
limits. Custom validators receive (arguments, subject, tool_name) and must
return TRUE, FALSE, a message, or list(valid, message). Tools listed in
approval_required are dispatched only when the approve hook explicitly
returns TRUE or list(approved = TRUE, id = ...).
Arguments
- allowed_tools
Explicit tool allowlist.
- schemas
Named list of compact JSON-Schema-like lists or validator functions. Supported schema fields are
required,properties, andadditionalProperties; property fields includetype,enum,pattern,minimum, andmaximum.Optional function receiving
(subject, tool_name, arguments).- validators
Named list of additional per-tool validator functions.
- side_effect_tools
Tools counted against
max_side_effects.- max_calls
Maximum tool requests in one guarded chat.
- max_side_effects
Maximum side-effecting requests in one guarded chat.
- spend_limits
Named numeric vector of maximum spend per tool.
- spend_argument
Name of the numeric argument carrying spend.
- approval_required
Tools that require an explicit approval decision.
- approve
Optional approval function receiving
(subject, tool_name, arguments). The application is responsible for authenticating the human approver and preventing approval replay.- show_stats
Show construction time and available usage metrics.
