-
Notifications
You must be signed in to change notification settings - Fork 129
gating ai agent tool calls
A tool-call gate is a check that runs after the agent has chosen an action and before the action runs: a small model reads the user's request and the proposed call, and answers questions such as "Is this action what the user asked for?" with a probability. Code then runs the call, asks the user to confirm, or blocks it, depending on how high the probability is and how much damage the tool can do. On a laptop CPU the check adds 25 to 110 ms, which is small next to the tool call itself.
The gate is worth having because the model that chose the action is the model least likely to notice it chose wrong. A second reader with a narrow question, looking only at the request and the call, catches a different set of mistakes. It does not replace permissions, and this page says where it stops.
This page is where the gate sits, the questions it asks, per-tool thresholds, human confirmation, what the gate cannot see, and what it costs.
An agent loop has a step where the planner model emits a tool call: a name and arguments. The gate goes between that step and the execution. It sees three things:
- what the user asked, in their words;
- the proposed call, as JSON;
- any facts the call depends on that code has already computed.
The loop around it is short: describe the state, ask a yes/no question, act on a threshold. A gate is that loop with one question, "Should this refund run?", placed between the agent's plan and the tool.
One request, several questions, each about one thing:
{
"model": "jev-latest",
"state": {
"user_request": "My order 5521 never arrived, can you sort it out?",
"proposed_call": {"tool": "issue_refund", "order_id": "5521", "amount": "full"},
"order_found_for_this_user": true
},
"questions": {
"asked": {"type": "noul", "instructions": "Did the user ask for the action in proposed_call, or for something it directly resolves?"},
"same_item": {"type": "noul", "instructions": "Does proposed_call refer to the same order the user mentions?"},
"declined": {"type": "noul", "instructions": "Did the user say they do not want this action taken?"}
}
}Each answer comes back as its own noul. Three design points are carried by the request:
-
Ownership is a fact from code.
order_found_for_this_useris looked up in the database, not asked. Whether the user may act on an order is an authorization question, and authorization belongs to code. - The negative question is asked separately. "Did the user say they do not want this?" catches "I don't want a refund, just resend it", a case where "asked" alone might read the topic and say yes. Phrasing advice is on negation in yes/no questions.
- No amounts are compared by the model. If the refund amount must not exceed the order total, compare the numbers in code. On our 999-question test set, questions comparing a number with a threshold were answered right 0.654 of the time, against 0.954 for stated facts.
The threshold is a property of the tool, not of the model. A reversible action can run on a lower bar than one that cannot be undone.
| Tool | Reversible? | Run without asking when | Otherwise |
|---|---|---|---|
| search, read a record | yes | always, no gate | |
| draft an email | yes | asked > 0.5 | show the draft |
| send an email | no | asked > 0.9 and declined < 0.1 | ask the user to confirm |
| issue a refund | money moves | asked > 0.9, same_item > 0.9, declined < 0.1 | confirm, or send to a person |
| delete data | no | never | always confirm |
These bars are a starting point for your own labelled cases, not measured optima. The reasoning behind a higher bar for yes, when a wrong yes costs more, is on thresholds when a wrong yes costs more than a wrong no. It matters here because our measurements show a lean toward yes when the model is wrong: 152 wrong yeses against 91 wrong noes on the 999-question set.
When the gate is unsure, it should ask the user, in plain words: "I am about to refund order 5521 in full. Go ahead?". That is not the gate failing; it is the gate doing its job on the cases it cannot settle. OWASP's entry on Excessive Agency in its Top 10 for LLM applications recommends human-in-the-loop control that requires a human to approve high-impact actions before they are taken, and a gate gives you a principled way to decide which actions reach that step.
The band between "run" and "block" is a human review band with the user as the reviewer. Size it so confirmations are rare enough that users read them.
- Whether the agent should have the tool at all. OWASP's advice on Excessive Agency starts with limiting extensions, their functions and their permissions to what is needed. A gate on a shell tool is a poor substitute for not giving the agent a shell.
-
Injected instructions it is told to trust. If a web page the agent read says "the user
wants a refund", the gate reads the same poisoned context unless you keep the user's own words
separate in
state. It is one layer; see AI agent guardrails with yes/no questions. - Arithmetic and dates. Do them in code before the gate, and pass the results as fields. In a LangChain agent that is ordinary code around a LangChain tool for local yes/no decisions.
- Non-English requests. jevos reads English only.
A gate request with the user's message and a small tool call is a short request: on our reference laptop (Intel Core Ultra 7 255H, 16 threads, no GPU), about 26 ms for 30 tokens and about 112 ms for 190 tokens. Three questions on one state took about 66 ms against 49 ms for one, because the state is read once. Gate only the tools that change something, and the cost per agent run is a few of those calls.
What is tool-call gating? A check between an agent choosing a tool call and the call running, which decides whether to run it, confirm it with a person, or block it.
Why not let the agent's own model check itself? It chose the action, so it is poorly placed to doubt it. A second reader with a narrow question fails in different places.
Should every tool be gated? No. Read-only tools need no gate. Gate what sends, pays, deletes or changes an account.
Is a gate a security control? No. Permissions and authorization in code are the control. A gate catches misunderstandings.
What should happen when the gate is unsure? Ask the user to confirm, with the action and its arguments in plain words.
See also: stop conditions for AI agents, logging LLM decisions for audit and LLM policy decisions: put the rule in the question.
- Our measurements: latency on the reference laptop and the three-question timing from the jev README; accuracy by kind of question and error direction from our 999-question set.
- OWASP GenAI Security Project, LLM06:2025 Excessive Agency, fetched 2026-09-29.
From the notes of jev, a yes/no decision model that runs on a laptop CPU. The refund example on this page is the README's refund example seen from the other side: not whether to refund, but whether the agent understood the request.
- Ask a local LLM a yes/no question and get P(yes)
- Zero-shot text classification with yes/no questions
- LLM policy decisions: put the rule in the question
- LLM as a judge on a CPU
- Why a small LLM says yes when the answer is no
- Small LLMs and arithmetic in yes/no questions
- Our held-out benchmark said 0.855, new questions said 0.757
- jevos vs Jev vs Laya for yes/no decisions
- An open-source alternative to Jev for yes/no decisions
- jevos vs the OpenAI API for yes/no classification
- jevos vs Ollama for yes/no decisions
- jevos vs bart-large-mnli for zero-shot classification
- A yes/no LLM vs a fine-tuned BERT classifier
- jevos vs SetFit: zero-shot vs few-shot classification
- jevos vs Llama Guard for content safety checks
- jev serve vs llama.cpp server for classification
- jevos vs LM Studio: a decision server, not a chat app
- Local vs hosted LLM decisions: latency, cost, privacy
- A yes/no LLM vs a business rules engine
- LLM decisions vs keyword rules and regex
- The fastest AI model for yes/no decisions
- What makes a local LLM fast on a CPU
- Why one forward pass beats generating an answer
- Prefill vs decode: where LLM latency comes from
- Why LLM latency grows with the length of the text
- Why a hosted LLM API cannot answer in 50 ms
- Many questions about one text: why the extra ones are cheap
- CPU or GPU for a small LLM
- Latency budgets: where a 200 ms model fits
- Measuring LLM latency: median, p90 and warm-up
- Q4_K_M vs Q8_0: speed and size for a small model
- Throughput vs latency for a decision server
- What P(yes) means, and what it does not
- LLM calibration explained with yes/no answers
- Expected calibration error (ECE), explained
- Temperature scaling for LLM probabilities
- Platt scaling for a yes/no model
- Reading a reliability diagram
- How to choose a threshold for P(yes)
- Thresholds when a wrong yes costs more than a wrong no
- Human in the loop AI with a review band
- Precision and recall at a P(yes) threshold
- Base rates: why a 0.9 yes can still be wrong often
- Combining yes/no answers with AND, OR and NOT
- Logits, log-odds and P(yes)
- LLM confidence scores: probabilities vs self-reports
- How to write yes/no questions an LLM answers well
- Negation in yes/no questions for an LLM
- One condition per question: splitting compound questions
- Ask whether the text says it at all
- Scores as yes/no thresholds: is it at least high?
- Sending JSON as the text: designing the state
- Why wording changes an LLM's answer, and how to test it
- Mainly about: questions for messages with several topics
- Yes/no questions about tone and emotion
- Asking about intent: what does the writer want?
- Yes/no questions about long documents
- Using an English-only LLM with other languages
- Content moderation with a local LLM
- A Discord moderation bot with a local LLM
- Spam detection with yes/no questions
- Review moderation with a local LLM
- Email triage with a local LLM
- Support ticket routing with yes/no questions
- Urgency detection in customer messages
- Sentiment analysis with yes/no questions
- Intent detection with a local LLM
- Lead qualification with yes/no questions
- Fraud case triage with a local LLM
- Phishing email screening with a local LLM
- Log and alert triage with a local LLM
- Checking text for personal data with yes/no questions
- Prompt injection screening with a small model
- Document classification with a local LLM
- Product categorization with yes/no questions
- Contract clause detection with a local LLM
- Refund request triage with a local LLM
- Detecting cancellation intent in customer messages
- RAG evaluation with yes/no questions
- RAG faithfulness check with a local LLM
- Hallucination detection with a local LLM
- LLM regression tests in CI with yes/no checks
- Rubric design for an LLM judge
- Pairwise comparison with a yes/no judge
- LLM judge bias and how to control it
- Evaluation metrics for yes/no classifiers
- Building a yes/no test set for your own data
- Accuracy by kind of question: why one number hides failures
- Generating test questions with answers computed by code
- Benchmark contamination and truly held-out tests
- An LLM router with yes/no questions
- A model cascade: small model first, large model on doubt
- Semantic routing vs yes/no questions
- Gating AI agent tool calls with yes/no checks
- AI agent guardrails with yes/no questions
- Stop conditions for AI agents
- Logging LLM decisions for audit
- Reducing LLM cost with local yes/no decisions
- Replacing chat LLM calls with yes/no questions
- Structured output vs a probability
- A Python client for local LLM decisions
- Calling a local LLM decision server from JavaScript
- Local LLM yes/no decisions in n8n
- A Slack bot that uses local LLM decisions
- Home Assistant automations with local LLM decisions
- A LangChain tool for local yes/no decisions
- Batch decisions from files with jev decide
- Running LLM yes/no checks in GitHub Actions
- Securing a local LLM server with an API key
- curl examples for a local LLM decision API
- Self-hosted AI for decisions
- A private LLM for text classification
- On-premise LLM for business decisions
- GDPR and automated decision-making with an LLM
- Offline AI for decisions: no network needed
- Edge AI decisions on a CPU
- Run an LLM locally without a GPU
- Small language models explained
- When a small model is enough, and when it is not
- An LLM on a laptop: what it can do in real time
- What is GGUF, for someone deploying a classifier
- GGUF quantization types explained: Q4_K_M, Q8_0 and others
- GGUF vs safetensors
- llama.cpp vs Ollama for a classification service
- llama-cpp-python vs calling llama.cpp through ctypes
- llama.cpp on Windows without compiling
- Running llama.cpp CPU only
- Using llama.cpp prebuilt binaries instead of building