High-Risk Tool

Deny an AI agent tool by name, such as delete_account, before it runs. High-Risk Tool matches the function name and does not read arguments.

Real-Time(Preventive)Checked before the call runs, so it can stop it

Some tools should not run just because a model decided to call them. High-Risk Tool denies a function by its name. The function body never runs.

Runs On
The SDK only
You Set
The function names to deny, such as delete_account.
Your Agent Sends
Nothing extra. The function name is enough.

What Happens

Tool the agent callsWith Block on
delete_accountDenied. The function does not run.
lookup_userNot on your list, so it runs.

A denied call shows in the Decision Log as Denied, and the trace is still saved. Observe and Warn record the match and let the call through.

Set It Up

  1. In the app, open Policies and click Create Policy.
  2. Choose High-Risk Tool and type the function name, such as delete_account.
  3. Set the mode to Block, then click Activate Policy.
  4. Wrap the agent with govern() and mark the function as a tool.

Good To Know

  • Only the function name is matched, ignoring upper and lower case. Arguments are never read, so this cannot allow a tool for some inputs and deny it for others.
  • Traccia does not delete anything and does not replace an identity provider.
  • This policy does not apply on the Gateway.

A worked example is in Stop A Dangerous Tool.

Next Steps

© 2026 Traccia.