---
title: "Tool allow-list"
description: "The deny-by-default list of tools an agent may call, each entry pinned by a hash of the tool's definition and bounded by resource scope, operation class, rate, egress destinations, data classes and…"
canonical: https://aigovernanceengineer.com/glossary/tool-allow-list
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Tool allow-list

The deny-by-default list of tools an agent may call, each entry pinned by a hash of the tool's definition and bounded by resource scope, operation class, rate, egress destinations, data classes and a checkpoint rule, evaluated by the tool gateway on every call. OWASP asks for such per-tool least-privilege profiles [1].

- Developed in: [ch. 23, The tool allow-list](https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list)
- Chapters: [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-tool-allow-list

## Sources

[1] Top 10 for Agentic Applications 2026 (ASI01 Agent Goal Hijack; ASI02 Tool Misuse and Exploitation; ASI03 Identity and Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities; ASI05 Unexpected Code Execution (RCE); ASI06 Memory & Context Poisoning; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents; Least-Agency; per-tool least-privilege profiles; tool poisoning of a legitimate tool's interface under ASI02, a tool compromised at the source under ASI04). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
