Skip to content

Tool permissions and governed connections

Tool Permissions define the outer boundary of what an agent may request. Gateway Tooling defines the governed adapters and connections capable of carrying out those requests. Neither one alone authorises execution.

Grant the smallest action set, resource boundary, data classification and environment required for the agent’s purpose. Separate read, search, create, update, delete, execute, external communication, data export, financial action, permission change and code modification. Broad wildcards require exceptional justification and stronger approval.

Review permissions after purpose, owner, supplier, model, environment or risk changes. Remove unused actions rather than relying on the agent not to call them.

A governed target or connection comes from the Gateway tooling catalogue available to the tenant and agent. It identifies a configured adapter and exact target under Gateway custody. A free-text name cannot create a connection or bypass readiness.

Before use, confirm:

  • the connector is approved and healthy;
  • credentials are stored by the governed connection, not the agent;
  • the target and environment are correct;
  • egress, resource and data boundaries are explicit;
  • monitoring and logging requirements can be met;
  • the connection owner and review date are current.

Runtime authority is the intersection of authenticated agent identity, active connection, Tool Permission, exact Runtime Access Policy, required approval and live Gateway checks. A permissive record at one layer cannot compensate for a missing or narrower record at another.

Changing a connection, credential, target, permission or environment can invalidate policy assumptions. Revalidate affected policies and simulations. Revoke or disable retired connections before removing descriptive records so runtime authority fails closed.