Tools
Decide which tool servers your agents may use and what each tool may do, from seeing what runs to enforcing it.
A tool server (an MCP server) gives agents tools: an issue tracker, a wiki, a database, a browser. The Tools view is where your organisation decides which servers agents may use and what each of their tools may do. You can start by watching what your fleet already runs, adopt what people rely on, review each tool, and only then switch enforcement on.
Administrators publish servers, review tools and change settings. In self-hosted AIOE, operators can see the Tools view too. In Mojo Up AI Cloud, a team's owners and admins do this.
Where it is enforced
AIOE is not in the path of a tool call. Each workbench and node decides every call from the policy it last pulled, and reports what it starts and what it refused or held. Machines need a release of AI Workbench that supports tool governance (0.37.0 or later); an older one ignores these rules.
The four things
| Thing | What it is | Where you meet it |
|---|---|---|
| Tool server | How a server is started or reached, and the credentials it needs, by name only. | Tools: publish, withdraw, adopt. |
| Tool | One thing a server offers, with a class: Reads, Changes or Destroys. | A server's page: review it, correct its class. |
| Setting | Allowed, Ask first or Off. | A server's page for one tool; Policies, "Tools Agents May Use", for defaults and rules. |
| Call | One use of a tool by an agent. | Audit, "Tool calls"; the call count beside each tool. |
A server is recognised by how it is started (its command and arguments, or its address), never by its name. A repository that calls its own server "tracker" does not inherit your review of the published tracker. Credentials are never part of a server's definition: name the environment variable or header, and each machine supplies the value.
From nothing to enforced
See
Machines report the servers they start. They appear under Seen in Your Fleet, with how many machines and projects use each. The figures at the top count servers published, tools waiting for review, servers seen but not published, and calls let through in the last 30 days.
Adopt or add
Open a seen server and choose Adopt to publish it as your organisation's. Or choose Add a tool server and describe one yourself: Runs on the machine (a command) or A web service (an address). Every workbench and node then gets it from the catalogue on its next sync.
A definition with a credential typed into its command or address is refused: move it to an environment variable first. If machines already start a server that way, the console masks the credential and warns you.
Review
Each tool waits for review until someone has read what it tells the agent. The server's page lists them under Waiting for Review; choose Reviewed on one, or Mark all reviewed. A review pins the tool's name, description and inputs. If the server later changes any of them, the tool waits again: agents are shown the words you reviewed, and a tool that changes things asks a person first.
Set
Each tool takes its class's default unless you give it a setting of its own:
| Class | Default |
|---|---|
| Reads (tools that only read) | Allowed |
| Changes (tools that change something) | Ask first |
| Destroys (tools that delete, or cannot be undone) | Off |
Set a whole class at once with Set all…, or one tool at a time. A server's own claim that a tool only reads is a hint: correct the class where it is wrong.
Watch
In Policies, the section "Tools Agents May Use" starts at Only record it: nothing is stopped, and each call that would have been refused or held is recorded. Look at Audit, "Tool calls", to see what enforcement would change.
Enforce
Switch "When a call breaks these rules" to Enforce and publish the policy. A call to a tool that is Off is refused; one that is Ask first waits in the project's inbox for a person.
The policy section
"Tools Agents May Use" in Policy holds:
| Setting | Choices | Default |
|---|---|---|
| When a call breaks these rules | Only record it, Enforce | Only record it |
| Tools that only read / change things / destroy things | Allowed, Ask first, Off | Allowed / Ask first / Off |
| A server that is not in the catalogue | Allowed, Ask first, Blocked | Allowed |
| What a recorded call keeps | Masked arguments, A digest only | Masked arguments |
| Rules | A server (or *), tool names (delete_* covers a family), one class, agents in some team roles, and what those tools are | none |
Try a Tool previews the decision for a call, using the same logic the machines use.
How a call is decided
- A withdrawn server: Off.
- A server not in the catalogue: what the policy says for unlisted servers. A rule that names it can only make that stricter.
- A published server: the tool's own setting and every rule that matches, the strictest winning; the class default when nothing says anything.
- A tool waiting for review that is not a Reads tool is never Allowed: Ask first at most.
- Under Only record it, the call goes through and what would have happened is recorded.
A project's owners can add rules on the project's Policy tab. Because the strictest wins, a project can turn a tool off but cannot allow one the organisation turned off.
Withdraw a server
On a published server's page, Withdraw turns every one of its tools off on every machine. Publish again restores it; Remove deletes it from the catalogue.
What is recorded
- Publishing, withdrawing, restoring and removing a server, and every review, setting and class correction, with the person who did it.
- Each call that was refused or held, and each call to a tool that changes or destroys, as reported by the machine. Arguments are masked, or kept only as a digest, as the policy says.
- Calls that were let through, counted by server, tool and hour.
Limits to know
- On a machine with no sandbox, an agent with a shell can still reach a server that needs no credential and is on the network. Keeping a server's credential in the workbench's gate, away from the agent, closes that for servers that need one: see Secrets.
- AIOE decides nothing at call time: a machine uses the policy it last pulled.