# AI Agent Tool Permissions & Policy — allowlists, deny rules, approval gates | Topic hub

How to decide and enforce what an AI agent may do: tool allowlists, deny-by-default postures, per-call permissions, approval gates, and where client-side rules stop holding. Every policy post, one page.

<div class="acp-section" style="padding-top:56px;">
  <div class="acp-container" style="text-align:center;">
    <div style="display:inline-block;padding:5px 16px;border-radius:100px;background:linear-gradient(135deg,rgba(79,70,229,0.14),rgba(6,182,212,0.10));color:var(--color-accent);font-size:12px;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;margin-bottom:16px;">Topic hub</div>
    <h1 class="acp-hero-h1" style="font-size:44px;margin:0 auto;max-width:780px;">Tool permissions &amp; policy</h1>
    <p class="acp-subtitle" style="max-width:720px;margin:18px auto 0;">
      An agent's real capability is its tool list, and policy is deciding what's on it: allow the core loop, deny the outward tail until first need, gate the irreversible behind a human. These posts cover the whole decision — how to write an allowlist, which tools to deny by default, why per-call permissions beat roles assigned at login, and the honest part most vendors skip: where client-side rules get bypassed and what enforcement outside the agent process looks like.
    </p>
    <p class="acp-subtitle" style="max-width:720px;margin:14px auto 0;font-size:14px;">
      The <a href="/tool-surfaces">Tool Surface Index</a> is the raw material — every tool Claude Code and Codex declare, grouped by blast radius. The incident-by-incident version is the <a href="/series/stop-your-agent">Stop Your Agent From… series</a>.
    </p>
  </div>
</div>

<div class="acp-section" style="padding-top:8px;">
  <div class="acp-container" style="max-width:780px;">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title" style="margin-bottom:20px;">Posts on tool policy</h2>
      <ol style="list-style:none;padding:0;margin:0;display:grid;gap:18px;">
        
        
        
        <li style="padding-bottom:18px;border-bottom:1px solid var(--color-border);">
          <a href="" style="font-size:17px;font-weight:600;color:var(--color-text-primary);text-decoration:none;line-height:1.35;"></a>
          <div class="acp-muted" style="font-size:14px;margin-top:6px;line-height:1.5;"></div>
        </li>
        
        
      </ol>
      <p class="acp-muted" style="margin-top:24px;font-size:14px;">
        Related: <a href="/blog/claude-code/">Claude Code</a> · <a href="/blog/mcp-security/">MCP security</a> · <a href="/three-axis-governance">how ACP policies work</a> · <a href="/blog">all posts</a>
      </p>
    </div>
  </div>
</div>

<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "CollectionPage",
  "name": "AI agent tool permissions and policy",
  "url": "https://agenticcontrolplane.com/blog/tool-policy/",
  "description": "Posts on deciding and enforcing what an AI agent may do: tool allowlists, deny-by-default postures, per-call permissions, approval gates, and the limits of client-side enforcement."
}
</script>
