Goal
Reduce unnecessary approval prompts while keeping explicit confirmation for tools that may change state.
Behavior
- Explicitly classified safe tools, such as documentation search and current-time lookup, run without confirmation.
- Potentially state-changing tools, including restarts and query execution, always require confirmation for each invocation.
- Unknown or unclassified tools require confirmation by default.
- Auto-approval rules and user preferences must not bypass mandatory confirmation for state-changing tools.
Acceptance criteria
- The exposed tool catalog has an explicit confirmation policy.
- Safe, state-changing, and unknown tools follow the same policy in all supported AI Assistant modes.
- Tests cover automatic execution, mandatory confirmation, rejection, and attempts to bypass mandatory confirmation.
Reference
YDB-3538 — AI Assistant architecture
Goal
Reduce unnecessary approval prompts while keeping explicit confirmation for tools that may change state.
Behavior
Acceptance criteria
Reference
YDB-3538 — AI Assistant architecture