Imp.ToolPolicy (Imp v0.5.0)

Copy Markdown View Source

The :tool_policy option of the tool-using programs (Imp.Predict.ReActV2, Imp.Predict.ReAct, Imp.Predict.RLM, Imp.Predict.CodeAct, Imp.Predict.Avatar): which of their tools the model may call.

A policy is one of:

  • :allow — every tool (the default).
  • a tool name, or a list of tool names — only those tools. Names compare as strings, so :lookup and "lookup" are the same tool.
  • a function of the tool name and the call's arguments (the string-keyed map the tool receives) that returns :allow or {:deny, reason}, the vocabulary Imp.Run's :authorize and Imp.ACP's :permission_policy use too.

A tool call the policy refuses is not made. The program records {:error, {:tool_denied, name, reason}} as that call's result, where reason names what denied it: :tool_policy for a name or list policy, or the reason a policy function gave. The same tag carries a run's :authorize refusal, with that callback's reason. The model reads that the tool was not allowed. A policy function that returns anything else refuses the call with the reason {:invalid_decision, value}, and one that raises or exits refuses it with {:tool_policy_error, name, reason}, so a broken policy never runs a tool.

Summary

Types

t()

A tool policy; see the moduledoc.

Functions

Returns :ok when policy allows calling the tool name with args, or {:error, {:tool_denied, name, reason}} or {:error, {:tool_policy_error, name, reason}} when it does not.

Types

t()

@type t() ::
  :allow
  | atom()
  | String.t()
  | [atom() | String.t()]
  | (atom() | String.t(), map() -> :allow | {:deny, term()})

A tool policy; see the moduledoc.

Functions

authorize(policy, name, args)

@spec authorize(t(), atom() | String.t(), map()) :: :ok | {:error, term()}

Returns :ok when policy allows calling the tool name with args, or {:error, {:tool_denied, name, reason}} or {:error, {:tool_policy_error, name, reason}} when it does not.