Availability
Availability determines whether a tool can run in a particular product surface. Depending on the system and rollout, surfaces can include:- Chat
- Copilot
- Custom Agents
- Helpdesk
- Project Plans
Interactive approvals
Approvals are organization-wide policies for tool calls made while a person is present. A tool can:- run without an extra prompt;
- require approval;
- be locked to a mandatory policy.
Background work
Custom Agents, AI Engineer, and project-planning workflows can run without a user at the prompt. They do not wait for interactive approval policy. Configure their tool boundary with Availability and the underlying role, system, scope, and tool access.Recommended review
1
Start from the role
Confirm who or which workflow should have any access to the system.
2
Classify the tool effect
Distinguish reads, protected reads, reversible writes, external communication, and high-impact changes.
3
Enable only the required surfaces
Keep background Availability off until the unattended workflow has been tested.
4
Configure interactive approval
Require a decision where a human should inspect the target or content immediately before the call.
5
Test the effective boundary
Use a representative non-admin user and a dry run or safe target.
6
Review the Audit Log
Confirm write outcomes are visible and attributable.