უსაფრთხო tool calling business AI აგენტებისთვის
როგორ უნდა მუშაობდეს tool calling production-ში: scopes, allowlists, confirmation gates, loop limits და least privilege.
Dali
Dali არის AI agent systems სტუდია. დავითი - engineering/product, ლიანა - operations/workflow fit. Production აგენტები არსებულ tools-ში.
David Hakobyan · Dali
პირდაპირი პასუხი
მიეცით აგენტებს პატარა tool allowlists, least-privilege credentials, explicit schemas, loop limits და human gates irreversible tools-ზე. Tool calling scopes-ის გარეშე არის ის, როგორ demos ხდება incidents.
Tool calling vs prompting
Prompting აწარმოებს ტექსტს. Tool calling აძლევს მოდელს structured actions-ის არჩევის საშუალებას (CRM update, search, send). Action layer არის ის ადგილი, სადაც business risk ცხოვრობს.
Allowlists და schemas
ყოველ tool-ს სჭირდება name, JSON schema, max frequency და owner. უარყავით free-form “run any code” production ops-ში.
Permissions
გაყავით read tools write tools-ისგან. გაყავით staging credentials. არანაირი god-mode service accounts agent runtime-ში.
Loop და spend limits
Max steps, max tokens, max tool calls, wall-clock timeout. Infinite replanning bug-ია, არა intelligence.
Assistants platforms
Hosted assistant APIs შეიძლება bootstrap-ში დაგეხმაროთ. მაინც თქვენ ფლობთ scopes-ს, logging-სა და gates-ს business actions-ისთვის.
როგორ ჯდება Dali
Dali აპროექტებს tool boundaries-ს discovery-ში: გადაწყვეტები.
FAQ
თითქმის არასოდეს პირდაპირ. უპირატესობა მიეცით constrained APIs-სა და audited mutations-ს.