Learn AI/AI engineering
LESSON 26 / 36Intermediate 35 min with practice

Structured outputs and tool boundaries

Treat generated instructions as proposals that still need validation.

WHAT YOU WILL LEARN
  • Validate a response schema
  • Use an explicit tool allowlist
  • Keep authorization outside model output

Structure makes errors visible

A structured response gives fields stable names and types. A valid JSON object still needs schema checks: allowed keys, required values, lengths, ranges, and permitted actions. Text that looks like JSON can fail to parse or contain a misleading extra field.

The application remains responsible for deciding what the user may do. A model cannot grant a user permission by producing a role field or claiming that an administrator approved an action.

Tools are controlled capabilities

Map allowed action names to functions you wrote. Validate arguments before dispatch, apply authorization, and bound runtime and output size. Avoid passing model-generated strings to eval, a shell, raw SQL, or arbitrary network URLs.

Start with read-only tools and make irreversible actions require a concrete, reviewable user decision. Separate the model’s proposed action from the code that authorizes and executes it.

PUT THE IDEA INTO CODE

A small experiment you can run.

The lookup is a fixed local capability. Neither the action name nor the slug is evaluated as code.

structured-outputs-and-tool-boundaries.py
import json
raw = '{"action":"lookup_lesson","slug":"vectors-and-similarity"}'
proposal = json.loads(raw)
known = {"vectors-and-similarity": "Vectors and similarity"}
def dispatch(value):
    if not isinstance(value, dict) or set(value) != {"action", "slug"}:
        raise ValueError("Unexpected schema")
    if value["action"] != "lookup_lesson" or not isinstance(value["slug"], str):
        raise ValueError("Unsupported action")
    return known.get(value["slug"], "Not found")
print(dispatch(proposal))
Copy code

Save the file, open your terminal in that folder, and run python structured-outputs-and-tool-boundaries.py. Use python3 or py if required by your installation. Setup guide

What to expect

The valid example returns Vectors and similarity.

YOUR TURN

Reject an unsafe proposal.

  1. Try an action named run_shell.
  2. Add an unexpected administrator field.
  3. Check that both fail before any tool executes.
Compare with a suggested solution

The allowlist rejects run_shell and the exact-key check rejects the extra field. In a real app, authorization must also use server-controlled user identity; schema validation alone is not access control.

CHECK YOUR UNDERSTANDING

One idea to take with you.

Where should a tool’s permission decision live?

Make it part of your progress.

Finish the practice and answer the knowledge check to mark this lesson complete.

Go deeper with primary documentation

Optional references for further study. This lesson and its examples were written for Artificials.

Python functools module