Блог

1 мин чтенияtutorial

Безопасный tool calling для business AI-агентов

Как tool calling должен работать в production: scopes, allowlists, confirmation gates, loop limits и least privilege.

Dali

Dali - студия AI agent systems. Давид ведёт engineering и продукт, Лиана - operations и fit процессов. Делаем production-агентов в tools, которыми команда уже пользуется.

David Hakobyan · Dali

Прямой ответ

Дайте агентам маленькие tool allowlists, least-privilege credentials, явные schemas, loop limits и human gates на необратимых tools. Tool calling без scopes - путь, которым demos становятся incidents.

Tool calling vs prompting

Prompting производит текст. Tool calling позволяет модели выбирать structured actions (CRM update, search, send). Action layer - место, где живёт business risk.

Allowlists и schemas

Каждый tool нуждается в имени, JSON schema, max frequency и owner. Отклоняйте free-form «run any code» в production ops.

Permissions

Отделяйте read tools от write tools. Отдельные staging credentials. Нет god-mode service accounts в agent runtime.

Loop и spend limits

Max steps, max tokens, max tool calls, wall-clock timeout. Infinite replanning - это bug, не intelligence.

Assistants platforms

Hosted assistant APIs помогают bootstrap. Вы всё равно владеете scopes, logging и gates для business actions.

Как помогает Dali

Dali проектирует tool boundaries в discovery: solutions.

FAQ

  • Почти никогда напрямую. Предпочитайте constrained APIs и audited mutations.