Separating Agent Tool Calls from Authorization and Evidence As LLM applications evolve from chat interfaces into agentic systems that call tools, APIs, workflows, and external services, the security question changes. The question is no longer only: Did the model generate the right answer? It becomes: What happens when model output turns into an actual action? For example, a model may generat