YOUR SCENARIO
How would you approach this?
An agent sometimes uses update_customer when a user only asks to see a customer record. Both tools accept an account ID and their descriptions overlap. How would you fix the interface and execution path?
This is an illustrative practice scenario. State any additional assumptions in your answer.
Make your case first.
Clarify the goal, identify the biggest uncertainty, outline an approach, and explain how you would test it. Spend about 8 minutes before opening the reference.
Your notes are not submitted or saved. Keep a copy before leaving this page.
Reveal reference approach Clarifying questions, decisions, and tradeoffs
Clarify before designing.
- Was the write merely proposed, or did the application execute it?
- How are user intent, authenticated identity, and action permissions checked?
One defensible approach
- 01
Contain the execution risk
Inspect affected traces and disable unintended writes while investigating. Require the execution layer to validate allowed action, resource scope, and arguments before side effects. A correctly shaped tool call is still only a proposal.
- 02
Make the tools distinguishable
Give reads and writes distinct names and concise descriptions of when each applies. Require explicit fields for updates and reject unexpected arguments. Return structured, bounded results and actionable errors rather than ambiguous success strings.
- 03
Evaluate near misses
Test read-only requests, ambiguous instructions, denied resources, and malicious text in retrieved data. Check both tool selection and resulting state. Confirm rejected calls cannot enter the write function.
Explain the tradeoff
More tools can improve specificity but also increase selection burden. Expose only the relevant authorized operations for the current task.
Common mistakes
- Solving a permission defect only by rewriting the system prompt.
- Accepting an account ID because the model supplied valid JSON.
KEEP THE CONVERSATION GOING
Try the follow-ups.
- How would you design confirmation for a permitted write?
- What should the agent see when access is denied?
Review your own answer.
Tick the points you covered. This is a reflection checklist, not an automated score or a hiring prediction.
Check the underlying concepts.
The scenario and reference approach were written for SaveMyToken. These sources support the technical concepts; they do not report this question being asked by an employer.
Anthropic: Writing effective tools for agents ↗OpenAI: Structured model outputs ↗