Skip to content

Tools and approvals

Every tool an agent can call has a class, and every session has a tool mode. Together they decide which tools the model is offered and which ones ask the user first.

Where tools run

Kind Runs Declared by
Host tools In your application, on the user's device: they read or change the open document, page or program Your code, with the SDK
Local MCP servers On the user's device, as separate processes the agent starts (.NET SDK) Your code; the server's policy for the agent decides whether they may start
Server tools On the Fadenstack server: the MCP servers IT has registered IT, in the console

The model sees one list of tools. Host tools run in your code, server tools run on the server, and the SDK hands each call to the right place.

Tool classes

Every tool has one of four classes. The class says what the tool may do.

Class Means
Read Reads and changes nothing
Write Changes something that can be changed back
Destructive Changes something that cannot easily be changed back, or sends something away
Unknown Nobody said. Treated like the strictest class. Tools from local MCP servers are always Unknown, because an MCP server's own description of its tools is not trusted.

Tool modes

The user picks a mode for each session. Every session starts in Ask.

Mode Read Write Destructive Unknown
Off hidden hidden hidden hidden
Read only runs hidden hidden hidden
Ask runs asks asks asks
Auto runs runs asks asks
  • hidden: the tool is not offered to the model, and refused if the model calls it anyway.
  • asks: the SDK calls your approval handler before the tool runs. Without a handler, the answer is no.
  • Approve for this session stops asking for that one tool until the session ends.

The SDK sends the session's mode with each request, and the server applies the same table to its own tools.

Classes are ToolClass.Read, Write, Destructive and Unknown; modes are ToolMode.Off, ReadOnly, Ask and Auto. See Host tools.

Classes are "read", "write", "destructive" and "unknown"; modes are "off", "read_only", "ask" and "auto". See Tools.

What the server adds

  • The agent's contract. An administrator can list, for each agent, the host tools it may offer and their classes. The contract can make a tool's class stricter, never looser. When the contract is not empty, tools outside it are not offered. See Agents on the server.
  • New tools wait. When a new version of your application brings a tool the agent's published version does not know, the server holds it back until an administrator accepts it.
  • Tool rules. Administrators can deny a tool, require approval for it, or allow it, for host tools and server tools alike.
  • Mode limits Planned. In the Enterprise edition an administrator will be able to narrow the modes a user may pick for an agent.