Tool allowlist
Each agent has a documented tool allowlist. Tools outside the allowlist cannot be invoked at runtime.
The agent operates against a documented tool allowlist; tools outside the list are inaccessible at runtime. The allowlist is enforced by the integration layer, not by trusting the agent's own judgment. This is the foundational ACT control — without it, no other action-control is meaningful because the agent's capability surface is unbounded.
Allowlist is version-controlled, changes go through change management, and any tool call against a non-allowlisted target is logged and reviewed.