Безопасный tool calling для business AI-агентов
Как tool calling должен работать в production: scopes, allowlists, confirmation gates, loop limits и least privilege.
Dali
Dali - студия AI agent systems. Давид ведёт engineering и продукт, Лиана - operations и fit процессов. Делаем production-агентов в tools, которыми команда уже пользуется.
David Hakobyan · Dali
Прямой ответ
Дайте агентам маленькие tool allowlists, least-privilege credentials, явные schemas, loop limits и human gates на необратимых tools. Tool calling без scopes - путь, которым demos становятся incidents.
Tool calling vs prompting
Prompting производит текст. Tool calling позволяет модели выбирать structured actions (CRM update, search, send). Action layer - место, где живёт business risk.
Allowlists и schemas
Каждый tool нуждается в имени, JSON schema, max frequency и owner. Отклоняйте free-form «run any code» в production ops.
Permissions
Отделяйте read tools от write tools. Отдельные staging credentials. Нет god-mode service accounts в agent runtime.
Loop и spend limits
Max steps, max tokens, max tool calls, wall-clock timeout. Infinite replanning - это bug, не intelligence.
Assistants platforms
Hosted assistant APIs помогают bootstrap. Вы всё равно владеете scopes, logging и gates для business actions.
Как помогает Dali
Dali проектирует tool boundaries в discovery: solutions.
FAQ
Почти никогда напрямую. Предпочитайте constrained APIs и audited mutations.