Control which tools an AI agent can call at each step
AI Agentsper-step tool scoping for AI agents
At each point in the conversation the model can only see the tools you allowed there.
contextsgovernance
The claim
The model cannot call a tool that is not exposed at the current step. The tool is absent from its world rather than discouraged by an instruction, so neither a persistent caller nor a prompt injection can reach it.
Example · Annotated transcript
agentThanks for calling. Can I get your full name?
callerActually just put me through to a person.
Step collect_name exposes only save_name. No transfer tool exists this turn, so there is nothing for the model to call.
agentI'll get you to someone right after I have your name.
callerDana Whitfield.
save_name ran and the handler advanced to collect_reason, which does list transfer_to_human.
agentThank you Dana. What's this about, so I route you correctly?
callerA billing charge I don't recognise.
agentPutting you through to billing now.
A caller trying to skip the intake step, and failing.
An example written from the code beside it, not a recording. Replays at reading pace.
Why it holds
This is the difference between a rule and a constraint. A prompt saying “do not transfer before taking a name” is a preference the model may ignore under pressure. A step that does not list transfer_to_human in its functions makes transferring unavailable.
How it works
The agent declares one context with two steps. Each step calls set_functions([...]) with exactly the tools that may exist while it is active, and set_valid_steps([...]) with where it may go next. In the SWML the platform receives, that becomes a functions whitelist on each step under ai.prompt.contexts.default.steps:
All three tools are defined once on the agent (ai.SWAIG.functions); the step decides which of them the model can see. save_name writes the caller’s name to global_data from the handler (set_global_data action), so the next step has it without the model relaying it. transfer_to_human returns FunctionResult(...).connect(address), which the platform receives as a SWML action carrying a connect verb plus "transfer": "true".
One thing to know: a step that does not call set_functions *inherits the previous step’s whitelist*. Declare it on every step.
Limitations
Step advancement is model-evaluated against the step criteria. Tool visibility is not. If the order itself must be guaranteed, force the transition from inside the tool handler rather than trusting the criteria.
What to change first
Add a third step and give it a tool the earlier steps must not reach. Then try to talk the agent into using it early.