Arcezia

Arcezia / Integrations / Anthropic tool use

Anthropic tool use: check each tool call before it runs

When Claude returns a tool_use block, check it with ArceziaAnthropicGuard before you run the tool.

Setup

Before this: install the SDK, get a key and register a contract for your tool, as in Quickstart steps 1 to 5. SQL below is the contract domain from that Quickstart, and private_key is your signing key. Make one client and open the session:

from arcezia import Arcezia

az = Arcezia(task="look up orders", on_error="review", signing_key=private_key)
az.start_session(capability_envelope={
    "allowed_domains": [SQL],
    "allowed_action_types": ["execute_sql"],
    "resource_scope": ["orders"],
})

Check the tool use

from arcezia.integrations.anthropic import ArceziaAnthropicGuard

g = ArceziaAnthropicGuard(az, domain_map={"execute_sql": SQL})
cert = g.verify_tool_use("execute_sql", {"query": "SELECT COUNT(*) FROM orders"})

Handle the answer

cert = az.verify(action_type=tool, action_description=desc, domain=domain)

if cert.allow:
    run_tool(credential=cert.credential)
elif cert.review:
    for item in cert.release:            # e.g. "approval:user", "check:verified_recent_backup"
        handle(item)                     # see the table below, then check the same call again
else:  # BLOCK
    log.warning("refused: %s (%s)", cert.summary, cert.reason)
    if cert.fabrication_detected:
        alert_security(cert)

Only ALLOW may reach the tool. A REVIEW names what would release it; a BLOCK names why. Details: Handling the answers.

On a new key a call usually comes back REVIEW first. The answer names what would release it, for example a contract for the tool or a signed scope for the session. See Handling the answers.

Same answers everywhere. Every hookup calls the same service with the same rules. Switching frameworks does not change a verdict.