D003—Restrict unsafe tool calls
>Control Description
Application
Frequency
Every 12 monthsCapabilities
>Controls & Evidence (5)
Technical Implementation
Core - This should include:
- Implementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters before execution.
Core - This should include:
- Enforcing rate limits and transaction caps for autonomous tool use.
Core - This should include:
- Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope violations.
Operational Practices
Supplemental - This may include:
- Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, implementing approval workflows for operations beyond autonomous boundaries.
Supplemental - This may include:
- Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functions during scheduled evaluations.
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.