Use Cases and Playbooks
These playbooks walk through putting tool policies to work on real systems. Each one builds tools or agents from your AI client, then sets the rules that kee...
These playbooks walk through putting tool policies to work on real systems. Each one builds tools or agents from your AI client, then sets the rules that keep them inside the lines you choose.
Playbooks
Put guardrails on warehouse queries
Your team can ask the data warehouse anything, which means the AI can also be asked to change it. This playbook gives everyone open access to read, blocks statements that change or delete data, keeps payroll and HR schemas off limits, stops oversized result sets, and lets your data engineering group through where others are blocked.
Control where your tools can send data
Tools that talk to your ERP, carrier portal, and supplier APIs take a web address as a parameter, and the AI chooses it. This playbook limits requests to an approved list of hosts, closes the gaps that lookalike addresses slip through, restricts destructive requests to the team responsible for them, and keeps agent email inside your company and named partners.
Build a query intent classifier
Patterns look at how a query is spelled, not what it does. This playbook builds a small tool that labels a query as read, write, or admin, then uses it as a classifier so that your rules act on intent. It covers handling low confidence, skipping the classifier for plain selects, and setting up an agent that reviews its accuracy every week.
Give a scheduled agent only the access it needs
An agent that runs at 2am with tools that post to your ERP needs limits that do not depend on its instructions. This playbook allows a reconciliation agent the few tools it needs, caps the size of the adjustments it can post, blocks everything else for that agent alone, and builds a review app for what it hands to a person.
Choosing where to start
| If you want to | Start with |
|---|---|
| Stop a specific kind of call you have already seen | Creating a rule from a tool call |
| Protect a database or warehouse | Put guardrails on warehouse queries |
| Control which systems tools can reach | Control where your tools can send data |
| Judge a call by what it means | Build a query intent classifier |
| Limit an unattended agent | Give a scheduled agent only the access it needs |