WAF++ WAF++
Back to WAF++ Homepage

Tool Use

Agents must only use authorized tools. Tool use must be:

  • Checked (allowlist/denylist)

  • Logged

  • Limited (sandboxing, rate limits)

Guardrails

  • Tool whitelist only

  • Rate limiting per tool

  • Timeout and circuit breaking

Audit

All tool-use events must be in the audit log.