Tool-call gating
Before an agent runs a tool, decide whether to run it, ask the user to confirm or refuse — with more confidence required for risky actions — with the Tool-call Gating template.
Goal: let your agent act on its own when it is safe, and ask first when a wrong call would cost money, data or trust.
Create the decision
Templates → Tool-call gating → Create decision:
| Part | Content |
|---|---|
| State | user_request, tool, arguments (strings, required) |
verdict | choice — run, ask_user, reject, other |
risk | score — read-only, low, medium, high |
matches_request | probability — does the call do exactly what the user asked? |
| Policies | reject → block; ask_user → escalate; run and risk ≥ 3 and confidence < 0.9 → escalate; fallback escalate |
| Destinations | run_tool — function runTool on continue; confirm_with_user — reply with Yes / No buttons on escalate; rejected_reply on block |
Call it
curl -X POST https://api.dcision.io/v1/decisions/tool-call-gating \
-H "Authorization: Bearer $DCISION_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"state": {
"user_request": "Refund the duplicate charge on my last invoice.",
"tool": "issue_refund",
"arguments": "{\"invoice_id\": \"inv_2291\", \"amount\": 1200, \"currency\": \"BRL\"}"
}
}'{
"schema": "tool-call-gating",
"result": { "verdict": "run", "risk": "high", "matches_request": 0.83 },
"confidence": { "verdict": 0.81 },
"action": "escalate",
"destinations": [
{ "key": "confirm_with_user", "type": "reply", "status": "completed", "text": "Before I continue: should I run issue_refund with these details?", "buttons": ["Yes, go ahead", "No, cancel"] }
]
}Act on it
const d = await dcisionDecide("tool-call-gating", { user_request, tool: call.name, arguments: JSON.stringify(call.args) });
if (d.action === "continue") return runTool(call.name, call.args);
const reply = d.destinations.find((x) => x.type === "reply");
return agent.say(reply.text, reply.buttons); // on "Yes", run the tool; the agent never runs it on its ownTune it
- Describe your tools in
context— which ones are read-only and which move money or contact people. - Tighten the third rule for the riskiest tools:
risk≥ 4 and confidence < 0.95. - Dcision never gets access to the tool itself: the
functiondestination only says which function your code should call.
Document reranking
Score how well each retrieved document answers the query, sort candidates by a 0–1 rerank score and drop the irrelevant ones, with the Document Reranking template.
Reply confidence gate
Decide whether a drafted reply ships on its own (≥ 0.85), goes to a review queue (0.4–0.85) or to a person (< 0.4), with the Reply Confidence Gate template.