Skip to content
James Kirkman , home

Decision · Jul 2026

Safety by schema, withholding write tools instead of forbidding them

Adopted At work

Outside the approved channel the model never sees write tools at all. That saves ~1,500 tokens per call, keeps schemas cache-stable, and sits under four more layers of defense.

Context

CCE-SRE-Expert can do real work: file Jira tickets, stage edits, open pull requests, and write to Confluence. An agent with write access in a shared Slack workspace needs more than a polite instruction in its system prompt.

Options considered

  • Prompt-level rules: tell the model when it may write.
  • Permission-scoped tool schemas: only expose write tools where writes are allowed, and re-check at runtime anyway.

Decision

Defense in depth, with the schema as the first layer:

  1. Write tools are withheld from the model outside the approved channel. A tool the model can’t see is a tool it can’t misuse. It also saves about 1,500 tokens per call and keeps the tool schemas cache-stable.
  2. Runtime re-checks on every write, independent of what the model was shown.
  3. Draft-PR-only writes: the bot never merges. A per-file size cap, a block-list of sensitive paths, and a per-thread proposal cap shared across all write tools, so the model can’t cycle between tools to get around it.
  4. A deliberately awkward escape hatch for live Confluence writes: the bot proposes, shows a danger warning, and only executes after explicit confirmation in a later message, within a short window.
  5. A human-in-the-loop path: ask in Slack, the agent files a Jira ticket, stages edits, shows a diff, and opens a draft PR only on “ship it.”

Consequences

  • Safety and cost point the same way: smaller, stable schemas are cheaper and cache better.
  • The write path is reviewable end to end, since every change lands as a draft PR a human merges.
  • The same day the write path shipped, the bot missed a question because it didn’t know a core repository existed. The fix came with a rule I’ve kept since: every production miss becomes an eval case, and if the bot proposes a change to its own code, it has to propose a matching test.
  • The same idea later moved beyond tools. When a rule kept failing in the prompt, it moved into the harness as a post-answer verifier.
  • Nike In production

    CCE-SRE-Expert

    CCE SRE Mission Control's production agent: it answers with citations, debugs as well as it retrieves, and writes back only through a person.

    2026 – present