All guides

Control Which Tools Your AI Agents Can Use

Allow or deny tools and tool servers per policy, cap tool calls per run, and see exactly what an agent gets when a tool is not allowed.

11 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02How tool control works
  3. 03Allow and deny tools by name
  4. 04Allow and deny tool servers
  5. 05Servers that run tools for the provider
  6. 06Cap tool calls per run
  7. 07Try it in Monitor only first
  8. 08What happens on Enforce
  9. 09What callers see
  10. 10Test a denied tool
  11. 11Keep it as code
  12. 12If something goes wrong

01

What you'll set up

Agents are only as safe as the tools they can call. In about eleven minutes you will decide which tools and tool servers a policy allows, cap how many calls an agent run can make, and test the result before real traffic depends on it.

  • A list of tools an agent may use, and a list it may not
  • A list of tool servers an agent may reach
  • A cap on tool calls per run
  • A Monitor only trial before you enforce
  • A test that proves a denied tool is really denied

You need an owner or admin role and a policy bound to your agent's traffic. If you do not have one, start with the guide on creating your first policy.

02

How tool control works

Cloptima sits between your agent and the model provider. It reads the tools your agent offers to the model and the tool calls the model asks for. It does not run the tools. Your agent or your provider does that. Cloptima decides which of those requests are allowed.

One agent request
  1. 1Agent offers tools

    Names, and servers if labeled

  2. 2Policy checked

    Allow and deny lists

  3. 3Denied tools removed

    The model never sees them

  4. 4Model answers

    It may ask to call a tool

  5. 5Call checked

    A denied call is stopped and recorded

The same rules apply on every provider and tool format Cloptima supports, including OpenAI chat and Responses, Anthropic, Gemini, and Bedrock. Cloud and edge gateways judge a request the same way.

03

Allow and deny tools by name

Tool lists are on the Advanced step of the policy form, under Tool & modality restrictions. Enter tool names or wildcard patterns separated by commas.

FieldExampleWhat it does
Allowed tool nameslookup_customer, github_*Only matching tools may be offered or called. Leave empty to allow any tool that is not denied
Denied tool namesgithub_delete_*, run_shellMatching tools are never allowed. A deny wins over an allow

04

Allow and deny tool servers

A tool server is a group of tools, such as an MCP server. Server lists are in the same section of the form.

FieldExampleWhat it does
Allowed tool serversjira, slackOnly tools from these servers may be used
Denied tool serversremote-shellNothing from these servers is ever allowed

Server names come from the registry. The next guide shows how to register a server. A request that names a server that is not registered is treated as unknown.

05

Servers that run tools for the provider

Some providers run MCP tools themselves, for example OpenAI's mcp tool and Anthropic's MCP connector. The provider reaches the server directly, so the policy is where you decide whether that is allowed.

  • Name the server in the request, and list it under Allowed tool servers on the policy
  • Name the tools the model may use, so the allow and deny lists can judge each one
  • Leave require-approval on, so a person confirms calls the provider would make on its own

06

Cap tool calls per run

Agents can loop. Max tool calls puts a ceiling on how many tool calls one agent run can make.

  1. 1

    Open the policy

    Go to AI → Policies and open the policy bound to the agent.

  2. 2

    Open Agent-loop & execution caps

    On Advanced, find the section.

  3. 3

    Set Max tool calls

    Pick a number that fits a normal run. 10 to 25 suits many assistants.

  4. 4

    Pair it with Max loop iterations

    The same section has Max retry count and Max loop iterations for agents that retry or loop.

07

Try it in Monitor only first

Switch on tool rules without blocking anything. Cloptima records what would have been refused, so you can fix the lists before you enforce.

  1. 1

    Set Mode to Monitor only

    On the policy, choose Monitor only and fill in the lists.

  2. 2

    Run your agent normally

    Use it for a few days.

  3. 3

    Review what was recorded

    Open AI → Audit and look at the Policy Violations card for tool reasons.

  4. 4

    Adjust the lists

    Add tools your agent really needs. Deny the ones it should not have.

  5. 5

    Switch Mode to Enforce

    Do this on a policy bound to one agent first.

08

What happens on Enforce

On an enforcing policy, tool rules act in three places.

WhenWhat Cloptima does
The agent offers a denied toolThe tool is removed before the request reaches the provider. The model never sees it
The agent forces a denied toolThe request is refused with HTTP 403 and names the rule
The model asks to call a denied toolThe call is stopped and recorded as a policy violation

Removing a denied tool lets the agent keep working with the tools it may use. You do not have to change the agent.

09

What callers see

A refused request returns HTTP 403 with a reason that says which rule applied.

HTTP 403
{
  "error": "Your AI request was blocked because the requested tool use is not allowed by the active Cloptima policy.",
  "reason": "tool_denied",
  "violations": ["tool_denied"]
}
ReasonMeaningFix
tool_deniedThe tool is on the denied listRemove it from the denied list, or stop sending it
tool_not_allowedThe tool is not on the allowed listAdd it to Allowed tool names
tool_server_deniedThe server is on the denied listUse another server, or remove it from Denied tool servers
tool_server_not_allowedThe server is not on the allowed listAdd it to Allowed tool servers
tool_server_unknownThe server is not registered, or its name is missingRegister the server and use its registered name in the request
max_tool_calls_exceededThe run made more tool calls than allowedRaise Max tool calls if the behavior is expected

10

Test a denied tool

Prove the rule with a throwaway policy. Declare a tool you denied and see what the model receives.

  1. 1

    Deny a test tool

    On a test policy, add delete_repo to Denied tool names and set Mode to Enforce.

  2. 2

    Bind it to a test key

    Create a virtual key and bind the policy to it.

  3. 3

    Force the denied tool

    Send a request that selects the tool by name. You should see HTTP 403 with tool_denied.

bash
curl https://api.cloptima.ai/v1/ai/chat/completions \
  -H "Authorization: Bearer $CLOPTIMA_VIRTUAL_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-4o-mini",
    "messages": [{"role": "user", "content": "Remove the old repo"}],
    "tools": [{"type": "function", "function": {"name": "delete_repo", "parameters": {"type": "object", "properties": {}}}}],
    "tool_choice": {"type": "function", "function": {"name": "delete_repo"}}
  }'

Remove tool_choice and send the same request. The call now succeeds, and the model sees no tools, because delete_repo was removed before it reached the provider.

11

Keep it as code

Tool rules can live in Terraform with the rest of the policy.

main.tf
resource "cloptima_llm_gateway_policy" "support_agent" {
  name                 = "support-agent"
  mode                 = "enforce"
  allowed_tool_names   = ["lookup_customer", "create_ticket"]
  denied_tool_names    = ["delete_repo", "run_shell"]
  allowed_tool_servers = ["jira"]
  max_tool_calls       = 20
}

12

If something goes wrong

Most surprises come from names or from which policy applies.

What you seeLikely causeFix
A denied tool still worksThe policy is in Monitor only mode, or another policy appliesSwitch Mode to Enforce and check the bindings
The agent lost a tool it needsThe tool is not on the allowed listAdd its exact name to Allowed tool names
tool_server_not_allowed for a server you registeredA provider-run server must also be on the policy's allowed listAdd the server to Allowed tool servers
A deny list does not matchThe name differs from what the agent sendsCopy the exact name from the agent's tool definition

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial