← AI-102: Azure AI engineering, historical course
03 / 6 · 40 MIN

Agents, tools, and control

Retain authorization and operational accountability for agent-proposed actions.

Concept and mechanism

An agent combines instructions, context, and tools to advance a task. A model-returned function call is a structured proposal; application code remains responsible for interpreting and executing it. A schema validates names and types but does not establish that the user may act on that service. Before execution, check identity, scope, arguments, current state, and required approval. A read-only tool and a production-changing tool need different contracts. Expose only necessary capabilities and keep results traceable. If the model receives external text asking it to ignore rules, that text remains content without authority to grant privileges.

Guided application

In fictional incident support, first allow state collection and an evidence-based recommendation. An approved restart should use a traceable identifier and duplicate protection where supported. If the response is lost, do not assume the action failed: query state and reconcile before retrying. Define iteration, duration, and cost limits to prevent tool loops. When progress or evidence is insufficient, stop and route to an operator. Acceptance includes an unavailable tool, invalid arguments, unauthorized requests, ambiguous outcomes, and malicious responses from an external source. Operational reporting distinguishes requested action, accepted action, executed action, and confirmed recovery; these are different states.

IN PRACTICE

The agent finished its message, but the tool did not confirm the restart. User communication must keep the outcome unknown until evidence is obtained.

Common pitfalls

Valid JSON as approval; timeout as no execution; final answer as recovery; retries with new identifiers without reconciliation.

Related topics: Services, identity, and operations · Generation, grounding, and evaluation · Vision, metrics, and lifecycle

Take this idea with you

The application controls actions, limits, and evidence; operational decisions need an owner.

Create account

Reference: Agent function request application execution and output · AI-102 historical skills measured 2025-12-23; exam retired 2026-06-30