High-Risk Tool
Deny an AI agent tool by name, such as delete_account, before it runs. High-Risk Tool matches the function name and does not read arguments.
Real-Time(Preventive)Checked before the call runs, so it can stop it
Some tools should not run just because a model decided to call them. High-Risk Tool denies a function by its name. The function body never runs.
Runs On
The SDK only
You Set
The function names to deny, such as delete_account.
Your Agent Sends
Nothing extra. The function name is enough.
What Happens
| Tool the agent calls | With Block on |
|---|---|
delete_account | Denied. The function does not run. |
lookup_user | Not on your list, so it runs. |
A denied call shows in the Decision Log as Denied, and the trace is still saved. Observe and Warn record the match and let the call through.
Set It Up
- In the app, open Policies and click Create Policy.
- Choose High-Risk Tool and type the function name, such as
delete_account. - Set the mode to Block, then click Activate Policy.
- Wrap the agent with govern() and mark the function as a tool.
Good To Know
- Only the function name is matched, ignoring upper and lower case. Arguments are never read, so this cannot allow a tool for some inputs and deny it for others.
- Traccia does not delete anything and does not replace an identity provider.
- This policy does not apply on the Gateway.
A worked example is in Stop A Dangerous Tool.
Next Steps
© 2026 Traccia.