Reference

Tool Policies

Tool policies let you decide which tool calls are allowed in your workspace, down to the values inside each call. You write rules such as "block any warehous...

Tool policies let you decide which tool calls are allowed in your workspace, down to the values inside each call. You write rules such as "block any warehouse query that deletes data" or "members cannot send email outside the company", and Assist checks every tool call against them before the tool runs.

Who can manage tool policies

  • Workspace admins can create, edit, reorder, disable, and delete rules.
  • Workspace admins can change the workspace default and use the simulator.
  • Workspace members can view the rules on the Tool Policies tab, but cannot change them.

Who tool policies apply to

  • Everyone in the workspace, including admins. Admins are not exempt unless a rule says so.
  • Every way a tool can be called: chat, agents, MCP clients, workflows, and direct calls from sandcastle apps.
  • A rule can be narrowed to a role, a group, one person, or one agent.

What you can do with a rule

  • Allow or block a tool, a whole tool pack, or a pattern such as every tool starting with delete_.
  • Add conditions on the values in the call, such as the text of a query, the address an email goes to, or the host a request is sent to.
  • Limit the rule to calls that come from a specific place, such as agents only.
  • Ask another tool to judge the call. This is called a classifier, and it is useful when a pattern is not enough.
  • Write the message the AI sees when a call is blocked, so it can adjust instead of failing.

What tool policies cannot do

  • They cannot change a call. A rule allows or blocks; it does not rewrite values.
  • They cannot hide a tool. A blocked tool still appears in tool search, and the AI learns it is blocked when it tries to call it.
  • They cannot apply a rule change to a run that is already in progress. A long-running agent picks up changes on its next turn.
  • They cannot see inside tools that run entirely at the AI provider, such as a provider's built-in web search.
  • They do not replace the safety checks built into individual tools. Those still run underneath your rules.

How tool policies work

Rules sit in an ordered list, like a firewall. When a tool is about to run, Assist reads the list from top to bottom and stops at the first rule that matches. That rule's action, allow or block, decides the call. If no rule matches, the Default row at the bottom of the list decides. A new workspace has no rules and a default of Allow, so nothing changes until you add a rule.

A rule matches when three things are true: the call is to a tool the rule targets, the caller is someone the rule applies to, and every condition on the rule holds. Because the first match wins, order matters. Put specific exceptions above broad rules. For example, place "allow the finance group to run refunds" above "block refunds for everyone".

When a call is blocked, the tool does not run. The AI receives a short message explaining that workspace policy blocked the call, along with the message you wrote for that rule. The blocked call is recorded in Tool History with the rule that stopped it.

Where to find it

Open Permissions and select the Tool Policies tab. The Simulator tab next to it has a Tool call mode for testing rules.