> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentium.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Execution policy

> Apply mandatory host policy to validated tool calls and classify effects for plan mode.

`executionPolicy` is a host-owned gate for validated tool calls. It can allow, request approval, or deny execution. A per-tool approval exemption cannot override it.

```typescript theme={null}
import { Agent, defineTool, openai, type ExecutionPolicy } from "@agentium/core";
import { z } from "zod";

const readCatalog = defineTool({
  name: "read_catalog",
  description: "Read the local product catalog.",
  parameters: z.object({}),
  execute: async () => JSON.stringify([{ product: "notebook", price: 5 }]),
});
const policy: ExecutionPolicy = {
  decide: ({ toolName }) => ({ action: toolName === "read_catalog" ? "allow" : "deny" }),
  resolveEffect: ({ toolName }) => toolName === "read_catalog" ? "read" : "unknown",
};
const agent = new Agent({
  name: "catalog-reader",
  model: openai(process.env.OPENAI_MODEL ?? "gpt-6.1-sol"),
  tools: [readCatalog],
  executionPolicy: policy,
});
try {
  console.log(await agent.run("List the catalog.", { runMode: "plan" }));
} finally {
  await agent.close();
}
```

## Plan mode

`RunOpts.runMode` is `"execute"` or `"plan"`. In plan mode, a classified read may run, a write/execute/external effect is denied, and an unknown effect requires review. Supply an approval handler if your policy can return `ask`; see [approval](/agents/approval).

The host classifies the complete execution, including result transformers. Model arguments and remote annotations do not establish permission. A policy returning an invalid decision fails closed, and reviewed arguments cannot be mutated into a different call before execution.

Delegated policy is combined with the Agent's policy; it cannot relax it. Core Agent, controlled drivers, and supported local voice tools share this boundary. Arbitrary application callbacks and provider-executed remote tools remain outside local interception.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.