Lesson 16 / 25
Risk Tiers and Approvals
Classify tools as read, write or destructive and require approval accordingly.
Match friction to risk
Not every tool deserves the same care. Read tools can run freely. Write tools change state and often need logging or a confirmation. Destructive or irreversible tools (deleting data, sending money, emailing customers) should need explicit human approval. Unknown tools default to the strictest tier.
Layers of defence
Assume mistakes and manipulation will happen, and limit what any single failure can do.
An approval gate
This ran as shown. Reads pass; send_payment and the unknown tool both need approval, because unknown names fall to the strictest tier.
RISK = {"get_balance": "read", "convert": "read",
"send_payment": "write", "delete_account": "destructive"}
def needs_approval(name):
return RISK.get(name, "destructive") != "read"
print([needs_approval(n) for n in ("get_balance", "send_payment", "unknown_tool")])
Output:
[False, True, True]
Show the exact action
An approval prompt should show the tool and its real arguments ("send 5,000 INR to account 8841"), not a vague summary. People approve what they can see.
Quick check: How should an unknown tool be treated by default?
- As read-only
- As free to run
- As the strictest tier needing approval
- Ignore the safety rules
Answer
As the strictest tier needing approval — Failing closed means a forgotten classification cannot silently allow a risky action.