Agent Tool risk level
Every Tool declares a risk_level static and mandatory. It describes the maximum business consequence permitted by the contract, not data sensitivity or the likelihood that a particular call is dangerous.
The three levels
| Level | Meaning | Typical cases |
|---|---|---|
low | Observation, search, calculation, or proposal without durable mutation or external commitment. | Fetch/list/get, bounded search, calculation, allocation proposal. |
medium | Durable mutation that is still pre-commit, draft-like, reversible through a canonical transition, or compensable before an irreversible external commitment. | Create a company, suspend/reactivate, prepare a reversible draft or intent. |
high | Irreversible or externally observable commitment, financial movement, outbound communication, terminal decision, or external assertion that the model cannot reconstruct. | Send an email, execute a debit, finalize a dispute, approve a financial commitment. |
Classify the worst path
The level is determined by the riskiest path the Tool can execute. It does not vary according to the arguments of a particular call.
A Tool that sends an email remains high even if the message contains only “hello”: the effect has left Ormuz. Conversely, a read may remain low even if it returns confidential data; that confidentiality belongs to data protection.
If an argument causes the operation to move from medium to high, prefer separate Tools with different intents rather than dynamic risk.
Ce que risk_level does not replace
| Dimension | Contrat |
|---|---|
| Data sensitivity | security.class, agent_access et disclosure. |
| Business authority | Permissions, platform_access and the object's canonical contract. |
| Cost | Contrat economics and economic observations. |
| Execution consequence | risk_level. |
The risk level describes the maximum consequence of the Tool. It replaces neither business authority, permissions, disclosure policy, nor any user confirmation.
Classification examples
- Read an invoice:
low, even if some fields require a disclosure policy. - Create an invoice draft: generally
mediumas long as it has no irreversible external commitment. - Send an email:
high, because the recipient may receive it and no later action erases it. - Finalize a terminal business decision:
high. - Composite Tool : inherits the highest level of any path it can take.
Contract evolution
A change to risk_level is a change to the Tool contract. It must be visible in contract fingerprints, revision validation, and audit; it must not be applied silently to activities that have already been validated.