Reference

Using a Tool as a Classifier

Some calls cannot be judged by a pattern. Whether a query is destructive, whether a message contains customer data, or whether a request is in scope for an a...

Some calls cannot be judged by a pattern. Whether a query is destructive, whether a message contains customer data, or whether a request is in scope for an agent often takes judgment. A classifier lets a rule ask another tool for that judgment and then act on the answer.

Before you begin

  • You must be a workspace admin.
  • You need a tool that can act as the classifier. It takes some input and returns a result the rule can check, such as a label or a score. Any workspace tool can do this, including one you write yourself.
  • Choose a classifier that only reads and labels. See Choosing a safe classifier.

How a classifier works

When a call reaches a rule with a classifier, Assist:

  1. Checks the rule's target, who it applies to, and any ordinary conditions. If any of those fail, the classifier does not run.
  2. Builds the classifier's input from the values in the call.
  3. Runs the classifier tool.
  4. Checks the classifier's result against what the rule expects.
  5. Applies the rule's action if everything matched.

The call waits while the classifier runs, so a classifier adds time to every call the rule covers.

Steps

1. Add a classifier to a rule

In the rule editor, click Add classifier. To turn an existing condition into a classifier, select Classifier at the top of the condition.

2. Choose the classifier tool

Click Classifier tool, start typing, and press Tab to complete the name. Once the tool is recognized, the line under the field lists the parameters it takes.

3. Set the input

The Input box holds the values sent to the classifier. Any text value that starts with $ is read from the call being checked:

Input valueWhat the classifier receives
"$.query"The query parameter of the call
"$.to[*].email"Every recipient address in the call
"$"The whole call
"snowflake"The text snowflake, exactly as written

Click Draft input to fill the box from the classifier's parameters. Parameters with the same name as one in the guarded tool are connected for you. Review the rest and fill them in.

4. Set what to expect

Under Expect, add one or more clauses that check the classifier's result. Each clause has a path, an operator, and a value, the same as an ordinary condition. For example:

  • label equals destructive
  • confidence gte 0.8

All clauses must hold. Click Add clause to add another.

Tools do not declare the shape of their results, so the paths here are typed by hand. Run the classifier once to see what it returns before you write the clauses.

5. Choose what happens on error

Under On error, choose what the rule does if the classifier cannot be run, fails, or takes too long:

SettingEffect
Fail closedThe condition counts as matched. On a rule that blocks, the call is blocked.
Fail openThe condition counts as not matched. The call continues to the next rule.

Fail closed is the default and the safer choice for rules that block.

Set Timeout (ms) to how long the classifier may take. The default is 3000, and the most you can set is 30000.

6. Test it in the simulator

The test box in the rule editor skips classifiers. Save the rule, then use the simulator. The simulator runs the classifier for real and shows what it returned.

Choosing a safe classifier

A classifier runs outside the rule list. This is what keeps a classifier from triggering rules that call the classifier again. It also means two things:

  • A rule that blocks the classifier tool for users does not stop it from being used as a classifier.
  • The classifier receives values that the AI wrote, because its input is built from the call being checked.

Choose classifier tools that only read and label. Do not use a tool that sends messages, writes data, or changes anything, because the AI could influence what it does.

Tool search and tool execution helpers cannot be used as classifiers.

Keeping classifiers fast

  • Target the rule at a specific tool so the classifier runs only where it is needed.
  • Put an ordinary condition on the same rule when you can. Ordinary conditions are checked first, and the classifier is skipped when one fails.
  • If two rules use the same classifier with the same input, it runs once per call.

Next steps