Before I let an agent call a tool in prod, I ask these five things

Reddit r/AI_Agents Tools

Summary

A practitioner shares a pre-production checklist for letting AI agents call state-changing tools: clear principal identity, explicit delegation scope, tool listing disclosures, app readiness (idempotency, audit trails, per-agent auth), and fail-closed behavior when policy or auth is down.

I stopped collecting "cool MCP servers" and started a boring pre-prod checklist. Sharing in case it saves someone a messy Tuesday. Before an agent can call a tool that can change state, I want answers to: Who is the principal? A stable agent (or subagent) identity, not "the shared service account we use for everything." What was delegated for this run? Read vs write vs destructive, decided before the first side effect, not inferred after the fact. What does the tool's listing actually disclose? Same columns every time: auth path, side-effect class, last-reviewed / version. Unannotated side effects get treated as destructive. Is the app behind the tool ready? A pretty wrapper doesn't fix missing idempotency, no audit trail of writes, or auth that can't tell which agent did what. What happens when policy/auth is down? Fail closed. In-harness hooks that fail open are fine for audit; they're not a control plane. When I shortlist tools I want those columns visible. If they aren't, a three-row spreadsheet plus one real task on each shortlisted tool beats a vibe ranking. Curious what you'd add or cut for a solo / small-team setup.
Original Article

Similar Articles