Expose an Agent read Tool

A read Tool must produce a useful, bounded observation for an Agent task, not a generic listing facade over merchant data.

Bon pattern

  • Choose an intent that the model can select, for example searching for candidate invoices for a specific task.
  • Return a stable shape with explicit limits, ordering, and pagination.
  • Preserve classification, provenance, and the distinction between partial, empty, and unavailable results.
  • Accepted IDs must come from references that are already visible/authorized or from a search that is itself authorized.
  • Keep risk_level=low for a read without durable effect; data sensitivity remains a separate dimension.

Anti-pattern

JavaScript
manage_resource({ object, operation, query, fields })

A universal Tool makes intent, authority, and completeness difficult to understand and audit. Prefer targeted business observations.

See Design an Agent Tool.