AI security

Govern AI agent tools before production

Tool access is part of an agent's effective identity. Before blocking anything, learn which tools are declared, which are invoked, and which agents actually use them.

By Munis Badar · ·

Declarations are not invocations

A model may receive a tool definition without ever calling it. The Skills & Tools view separates declarations from invocations so review teams can prioritize real usage instead of theoretical exposure.

Observe first, then enforce

Turn on Capture tool use in AI Firewall -> Agent Config -> Tool governance. Start with Observe only, review sources and unreviewed tools, then switch to Block calls outside the allow-list when the policy is ready.

Use narrow custom skills

Custom skills should describe one meaningful operation with a predictable payload. AI-FW validates curated payload schemas, audits the decision, and relays the instruction to the target agent instead of executing arbitrary skill code in the gateway.

Keep the evidence useful

Tool arguments are represented by metadata and digests. This supports review and correlation without turning the governance layer into an unrestricted second content store.