Map each tool schema to an execution surface in your registry, then enforce PERMIT / DENY / SILENCE on the outbound request.
Authorize the concrete function invocation, not only the model session.
Map each tool schema to an execution surface in your registry, then enforce PERMIT / DENY / SILENCE on the outbound request.