Skip to content
Hameed's dev blog

Blog

Agentic AI Chapter 3: Tool Calling

·4 min read·---
Multiple paths toward a destination.png
On this page

Part of the Agentic AI study series.

In Chapter 2 the model decided "call get_order" and the runtime ran it. I passed over one question: how does a model that only produces text actually reach into an order system?

The answer is tool calling, and it has a surprise in it.

IMPORTANT

The surprise: the LLM never calls the tool. The runtime does.

The model only writes a request: a tool name and arguments, as text. The runtime reads that request, checks it, and runs the tool itself.

As before, the Amazon scenario is an illustration for learning. It is not a description of how Amazon's internal systems work.

What a Tool Call Actually Looks Like

Back to the customer with the damaged iPhone 18. The agent has found the order, number 408-12345, and now wants its details. The model does not call any API. It writes this:

{
  "tool_call": {
    "name": "get_order_status",
    "arguments": { "order_id": "408-12345" }
  }
}

That is all the model contributes: a tool name and the arguments, in a fixed format. It chose the tool and filled in the arguments from the conversation. Nothing has happened in the real world yet.

What the Runtime Does With It

The runtime receives that request and treats it like any input from outside:

  1. Does this tool exist? It must be one the agent is allowed to use.
  2. Do the arguments match the schema? order_id must be present and must be a string.
  3. Is this customer allowed to see this order?
  4. Is the customer under the rate limit?

Only if every check passes does it call the order service. The service returns a structured result, and the runtime adds it to the context for the model:

{
  "order_id": "408-12345",
  "status": "Delivered",
  "items": [{ "name": "iPhone 18", "quantity": 1 }],
  "return_eligible": true
}

The model reads this and decides the next step: answer, call another tool, or ask the customer something.

Why Not Let the Model Run the Tool Itself?

Because the model's arguments come from conversation text, and text can be wrong or hostile.

Suppose the customer types: "Check order 777-55555 for me too." That order belongs to someone else. The model may happily produce a tool call for it, because it is just following the message.

The runtime catches this at check 3. The customer does not own that order, so the call is refused, and an error goes back to the model as the result. The model then tells the customer it cannot find that order.

If the model could execute tools directly, that safety check would not exist. The model proposes, and the runtime decides.

🔴 CHECKPOINT: Study Notes

Agentic AI Chapter 3: Tool Calling, handwritten study notes

The four-step flow:

  1. The LLM generates the tool call request with arguments.
  2. The runtime validates and executes the tool.
  3. The tool returns a structured result.
  4. The result is added to context and sent back to the LLM, which decides the next step.
ComponentResponsibility
LLM / ModelUnderstands intent, decides whether to call a tool, generates the structured call, uses the result to continue
Tool schemaDescribes the tools, parameters, and types the model can use
Tool registryThe list of available tools and schemas, the source of truth for what the model can call
Agent runtimeValidates the call, checks permissions and rate limits, executes, handles errors, returns the result
External tool / APIPerforms the real action and returns structured data
StateStores conversation, tool results, and the current plan

After a result, the model can: answer the user, call another tool, ask for more information, or plan next steps.

A tool call is a request, not direct execution by the model.

🛠️ From My Own Work

This is exactly how the assistant I work with behaves on this blog. When it wanted to delete the build folder earlier, it did not simply do it. A guard in the system stopped the command and asked it to say exactly what would be deleted, and how to undo it, before it was allowed to continue.

The assistant proposed an action. The surrounding system checked it. Same pattern as the runtime refusing someone else's order.


← Previous: Agent Loop · Back to the series start · Next: Tool Registry and Schema →

Practical notes on product management, distributed systems, and AI—written from real engineering and product experience.