Skip to content
Security and audit SQL recipe

Audit AI agent tool authorization decisions

Review allowed, denied, and approval-required agent tool decisions by risk class without collecting prompts, tool arguments, results, or credentials.

Beginneragent_tool_authorization_decisionsReviewed 2026-07-30Tested with Apache DataFusion 45.2.0

Reviewed by the Telemetry product team on . We checked the SQL syntax, required event fields, sample results, and limits on using the query. Who reviews this page

Question answered

Which agent tools are denied or routed to human approval most often?

Record each authorization decision where the application enforces it. This query counts denied, allowed, and approval-required calls by tool and risk class so you can compare policy changes without reading raw tool payloads.

Event schema

Fields the query expects

FieldTypeWhy it exists
timestamp_utcTimestampFinal policy-decision time in UTC.
workflowUtf8Versioned, low-cardinality agent workflow.
tool_nameUtf8Approved low-cardinality tool identifier.
action_classUtf8Controlled class such as read_only or external_state_change.
risk_levelUtf8Reviewed low, medium, or high risk class.
decisionUtf8Allowed, denied, or approval_required.
reason_codeUtf8Controlled policy reason without a free-form model explanation.
policy_versionUtf8Version of the policy contract used for the decision.
environmentUtf8Deployment environment.
DataFusion SQL

Copy the query

sql
SELECT
  tool_name,
  risk_level,
  COUNT(*) AS decisions,
  SUM(CASE WHEN decision = 'denied' THEN 1 ELSE 0 END) AS denied,
  SUM(CASE WHEN decision = 'approval_required' THEN 1 ELSE 0 END) AS approval_required,
  SUM(CASE WHEN decision = 'allowed' THEN 1 ELSE 0 END) AS allowed,
  100.0 * SUM(CASE WHEN decision = 'denied' THEN 1 ELSE 0 END)
    / NULLIF(COUNT(*), 0) AS denial_rate_pct
FROM agent_tool_authorization_decisions
WHERE timestamp_utc >= now() - INTERVAL '30 days'
  AND environment = 'production'
GROUP BY tool_name, risk_level
ORDER BY denied DESC, approval_required DESC, tool_name;

This read-only query is planned and executed against an empty typed table with Apache DataFusion 45.2.0. We review the synthetic sample output separately. Check field types, thresholds, and counting rules against your own data. Read the testing methodology.

Query result

Agent tool denial rate

Synthetic decisions keep denial rate beside approval and total volume for each tool.

tool_namerisk_leveldecisionsdeniedapproval_requiredalloweddenial_rate_pct
database_writehigh421150
filesystem_writehigh412125
web_searchmedium30030

Synthetic example output. Run the query against your own event schema and thresholds before using it for operational decisions.

Agent tool denial rate: static chart of synthetic denial_rate_pct values from the Audit AI agent tool authorization decisions example result
Download this SVG chart of the sample results for an article, runbook, or design review. Please credit Telemetry.

Reproduce the example

Download the sample data

The JSON bundle includes the event schema with field types, reproducible input rows, exact SQL, expected output, review notes, and engine version. The CSV contains the displayed result.

How the SQL works

  1. 1The decision is emitted by the authorization layer before execution, not inferred from the model's requested action.
  2. 2Tool name, risk level, reason code, and policy version use controlled values so policy changes remain comparable.
  3. 3Counts remain visible beside denial rate because a high percentage over a few decisions should not trigger an automatic escalation.

Edge cases to check

  • An expected denial can show policy working; define reviewed escalation conditions before alerting.
  • Log the final tool outcome separately so an allowed decision is not mistaken for successful execution.
  • Keep prompts, arguments, results, credentials, retrieved documents, and free-form policy explanations outside general telemetry.

Recommended dashboard

  • Bars: denial_rate_pct by tool_name
  • Stacked decisions: allowed, denied, and approval_required by risk_level
  • Trend: decision mix by policy_version and release

Alert guidance

Alert only on reviewed conditions such as a sustained high-risk denial spike, a novel tool class, or an overdue approval queue with sufficient volume.

Read alert setup

Set up the events this query needs

Related instrumentation and guides

Define the source data

Event schemas for this analysis

Continue the analysis

Run it on your events

Create a table, adapt the fields, and save the result

Start free, send structured events, and use the query result as a chart, shared dashboard widget, or alert input.

Get an API key