Tool-call gating

Before an agent runs a tool, decide whether to run it, ask the user to confirm or refuse — with more confidence required for risky actions — with the Tool-call Gating template.

Goal: let your agent act on its own when it is safe, and ask first when a wrong call would cost money, data or trust.

Create the decision

Templates → Tool-call gating → Create decision:

PartContent
Stateuser_request, tool, arguments (strings, required)
verdictchoice — run, ask_user, reject, other
riskscore — read-only, low, medium, high
matches_requestprobability — does the call do exactly what the user asked?
Policiesreject → block; ask_user → escalate; run and risk ≥ 3 and confidence < 0.9 → escalate; fallback escalate
Destinationsrun_tool — function runTool on continue; confirm_with_user — reply with Yes / No buttons on escalate; rejected_reply on block

Call it

curl -X POST https://api.dcision.io/v1/decisions/tool-call-gating \
  -H "Authorization: Bearer $DCISION_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "state": {
      "user_request": "Refund the duplicate charge on my last invoice.",
      "tool": "issue_refund",
      "arguments": "{\"invoice_id\": \"inv_2291\", \"amount\": 1200, \"currency\": \"BRL\"}"
    }
  }'
200 OK (abridged)
{
  "schema": "tool-call-gating",
  "result": { "verdict": "run", "risk": "high", "matches_request": 0.83 },
  "confidence": { "verdict": 0.81 },
  "action": "escalate",
  "destinations": [
    { "key": "confirm_with_user", "type": "reply", "status": "completed", "text": "Before I continue: should I run issue_refund with these details?", "buttons": ["Yes, go ahead", "No, cancel"] }
  ]
}

Act on it

const d = await dcisionDecide("tool-call-gating", { user_request, tool: call.name, arguments: JSON.stringify(call.args) });
if (d.action === "continue") return runTool(call.name, call.args);
const reply = d.destinations.find((x) => x.type === "reply");
return agent.say(reply.text, reply.buttons); // on "Yes", run the tool; the agent never runs it on its own

Tune it

  • Describe your tools in context — which ones are read-only and which move money or contact people.
  • Tighten the third rule for the riskiest tools: risk ≥ 4 and confidence < 0.95.
  • Dcision never gets access to the tool itself: the function destination only says which function your code should call.

On this page