Tool Calls, Permissions and Workflows
Understand what happens when an assistant calls a tool, give it only the permissions the task needs, approve or reshape what it asks to do, split work into checked pieces, and recover when a step fails.
- Lessons
- 8
- Exercises
- 47
- Minutes
- 50
- 1
What a Tool Call Is
After this lesson you can say what happens between a coding agent deciding to read a file and the answer you see, and why the middle is where things go wrong.
DebugFill blankMultiple choiceTrace - 2
Permissions and Least Privilege
After this lesson you can give a coding agent exactly the tools a task needs and nothing more, and explain why more is worse.
DebugCode orderMultiple choice - 3
Approve, Reject, Reshape
After this lesson you can handle a coding agent's request to act: approve it, refuse it, or narrow it, and know which one in ten seconds.
DebugFill blankMultiple choice - 4
Reading a Trace
After this lesson you can follow a tool trace step by step and point at the exact call where an answer went wrong.
DebugMultiple choiceTrace - 5
Pieces and Joins
After this lesson you can split a job into pieces a tool does well and chain them with a check at every join, so a wrong output never becomes the next input.
Code orderMultiple choiceTrace - 6
Judge the Output, Recover From Failure
After this lesson you can judge a tool's output in a minute with four fixed questions, and when it fails, name which of four failures it is and fix that instead of retrying.
DebugMultiple choiceTrace - 7
Checkpoint: The Board ReportCheckpoint
One workflow, built in eight decisions, with the failures you will meet along the way. Everything from the island, in one job.
DebugCode orderFill blankMultiple choice - 8
Boss: The Approval QueueBoss
Eight requests from a coding agent in one afternoon, on one ticket. Approve, reject, reshape, or read the trace first.
DebugCode orderFill blankMultiple choice