Skip to content

[Agent Loop] Registry-backed tool resolution + RBAC + audit + agent docs #852

Description

@heskew

Part of #612. Depends on #615, #618, #622.

Swap the agent loop's v1 caller-supplied opts.toolHandlers dispatch for registry-backed tool resolution — the half of #612 that makes toolMode: 'auto' the compressed-stack story (auto-discovered, RBAC-filtered, audited tools) rather than hand-wired handlers.

Scope / acceptance

Seam already in place (PR #848)

The loop's missing-handler split — DECLARED-but-no-handler → hard ClientError(400); UNDECLARED → recoverable "unknown tool" — maps directly onto the registry's resolvable-but-misconfigured vs unknown cases. The swap is a lookup replacement in runSingleToolCall, not a loop rewrite.


🤖 Generated with Claude Code

Activity

  1. hegu-1 commented on Jul 15, 2026

    @hegu-1

    Registry-backed resolution plus caller identity is the right architecture. The edge case I would lock down is TOCTOU between discovery and execution.

    A resolved tool handle should carry at least the registry version and policy version used to expose it. When the model later calls the tool, the runtime should resolve again or re-authorize against the current versions. A tool removed from the registry, a revoked role, or a narrowed resource scope must fail closed even if it appeared in the model's earlier catalog.

    For the transaction log, I would record both the attempt and the effect:

    • requested tool name and arguments hash
    • resolved resource/verb/version
    • principal and policy decision
    • allowed/denied
    • effect/outcome reference

    That makes denials and stale-catalog calls visible rather than only auditing successful data writes. The tool registry template here includes risk and authority fields that could map cleanly onto the shared registry: https://github.com/hegu-1/enterprise-ai-os-architecture/blob/main/layers/05-executor/templates/tool-registry.json

  2. added theissue type on Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Fields

    Priority

    P2

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions