Context Before Catalog
User, agent, surface, and environment context arrive before the catalog opens.
Why it mattersTool visibility depends on who is asking and where they are acting.
Approved Does Not Mean Visible
A tool can be approved in the registry and still hidden from a specific agent.
Why it mattersRegistry approval and runtime visibility are different controls.
Policy Lens
Group, agent, client, delegator, and rule context focus the visible list.
Why it mattersDiscovery needs policy evaluation, not a static catalog dump.
Discovery Gate
tools/list passes through session and policy checks, with no bypass path.
Why it mattersUnauthorized tools should not leak through discovery before call-time denial.
Allowed Tools Tray
The agent receives only the tools that are visible, allowed, low-risk enough, and from the right source.
Why it mattersA small allowed list makes agent behavior easier to reason about.
Same Agent, Different Surface
The same agent can see different lists in an IDE, support bot, or production app.
Why it mattersClient surface changes risk and intent.
Environment Boundary
Dev and production discovery stay separated by environment.
Why it mattersProduction tools should not appear because a dev context happened to work.
Risk And Credential Mode
Risk tier and credential mode affect which tools become visible.
Why it mattersVisibility should account for how the downstream call would be authorized.
Session State
Active, expired, and step-up states can require a refreshed list.
Why it mattersA stale discovery list can become an authorization bug.
Delegated Authority
Delegated authority narrows the visible list through policy.
Why it mattersActing for someone else should not expand capability by accident.
Discovery Evidence
Discovery evidence records policy version, actor context, visible list, and audit receipt.
Why it mattersTeams need to explain why the agent saw a tool before it called it.
Discovery control
Make your agent's first view already governed
We are looking for teams who want policy-filtered tool discovery for real agent surfaces.
Start with one agent, one surface, and one tool family. We will define the allowed list, hide what policy excludes, run discovery through the gateway, and review the evidence together.
The goal is to make the agent's first view already governed.
Talk to our team
