Tool use
Why it matters
An agent with no tools can only advise. Once it can search, calculate, call an API or act inside a live system, it becomes a worker that finishes a task rather than describing how to finish it. It can check live data instead of guessing, and complete work end to end.
That changes what a founder can safely delegate. More tools mean more reach, but also more ways to cause harm. So each tool is scoped tightly, access is read-only where possible, and anything irreversible, such as sending or deleting, gets an approval step.
How to apply it
- List the actions the agent truly needs. Give it only those tools, not a broad grab bag.
- Grant read access before write access. A mistake then shows up in a report rather than as a live change.
- Put approval in front of anything irreversible. Sending an email, deleting a record and charging a card all wait for a person.
- Log every tool call. A wrong answer can then be traced to the exact lookup that caused it.
- Review the tool list every few months. Remove any tool that nothing calls any more.
What it is
Tool use is an AI agent reaching outside its own text to do something: search the web, run a calculation, call an API, read a file. The model recognises that it needs information or an action it cannot produce from memory, chooses a tool, uses it, and folds the result back into what it does next.
Function calling is the technical mechanism by which a model asks for a tool to be run, with the name of the function and its arguments. Tool use is the wider capability: the loop of deciding, calling, reading the result and continuing.
Common mistakes
- Giving the agent write access to everything on day one, because it was easier than choosing.
- Vague tool descriptions, so the model picks the wrong tool or calls one without need.
- No approval step on irreversible actions.
- Not logging calls, so nobody can explain a wrong answer afterwards.
- Trusting whatever a tool returns. Text fetched from a web page or an email can contain instructions, and the agent should treat it as data, not as orders.