Expose an authorized lookup
Host factory: supply a model and a lookup function already bound to the verified caller. The callback should enforce record ownership in your data layer. The caller owns the returned Agent and closes it after its runs finish.{ id: "ORD-1042", status: "shipped", deliveryDate: "Friday" } while developing. Ask about that ID, observe the tool call, and verify the answer agrees with the returned record. A schema validates the shape of an ID; the host lookup decides whether the caller may read it.
Choose toolkit tools deliberately
Host factory: the selected directory already exists. This read-only example enables the filesystem toolkit’s tools and leaves their implementation with the toolkit.Ask for a decision before an effect
Host factory: pass the action tool and an asynchronous decision function. This example delegates the decision to the caller; it does not automatically approve requests or invent an approval UI.More patterns
- Toolkits: public imports and available capabilities.
- MCP: tools supplied by an external protocol server.
- Jev toolkit: typed judgments exposed as tools.
- Execution policy: host policy and effect authorization.