Goal
Make tool use policy-driven, auditable, and safe for untrusted workflow inputs.
Scope
- Add per-workflow and per-tenant tool allowlists/denylists.
- Classify dangerous or side-effecting tools and require approval when configured.
- Validate tool input/output schemas, timeout/concurrency budgets, and payload limits.
- Add audit records for tool discovery, invocation, approval, rejection, and failure.
- Integrate policy decisions with Guardian and durable human approval.
Acceptance criteria
- A workflow cannot invoke a tool outside its effective policy.
- Dangerous actions can be blocked or routed to human approval.
- Invalid tool payloads fail before invocation and are recorded safely.
- Audit records are tenant-scoped, queryable, and redacted.
Priority
P1 — high-value security and operations enhancement.
See the PetalFlow 1.0.0 Readiness Report for the audit context.
Goal
Make tool use policy-driven, auditable, and safe for untrusted workflow inputs.
Scope
Acceptance criteria
Priority
P1 — high-value security and operations enhancement.
See the PetalFlow 1.0.0 Readiness Report for the audit context.