For each tool, define the permitted operation, input schema, output schema, timeout, retry limit, idempotency posture, and error handling. A read-only search has a different consequence from a record mutation, external message, or financial action. Validate parameters before execution and results afterward. Do not let the model reinterpret a provider error as success or repeatedly submit a mutation because the acknowledgement was ambiguous.
Retain enough evidence to reconstruct the material path without exposing secrets or unnecessary personal data. Useful records may include request identity, policy decision, source references, tool disposition, review decision, cost record, final outcome, and error state. Logs alone are not a proof model if they are unstructured, inaccessible to reviewers, or detached from the business object. Evidence should answer what happened, under whose authority, and with what accepted result.