FREE STUDY NOTES · AI-103

Agent oversight: approvals, constraints and tool-access controls

How to keep humans in the loop and limit what an agent's tools can do.

From Ultra Transcenders AI-103 by Tony Rough (publishing soon)

Agents can call tools and take real-world actions, so beyond content filtering you need controls over which tools they may call, who approves a call and what credentials they use. These settings live on the tools and guardrails in Foundry Agent Service.

MCP tool approval and allowed tools

Toolbox with a hosted agent

Common trap: Assuming require_approval: always on a toolbox tool stops the call server-side - the toolbox endpoint still executes the call unless your agent runtime enforces the approval.

Credentials and identity

Guardrail controls on actions

Get the whole book

This note is one section of Ultra Transcenders AI-103: Developing AI Apps and Agents on Azure, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free AI-103 glossary · All AI-103 study notes

More AI-103 study notes