This is the planning layer that runs before any future tool execution. Every tool action—send, write, payment, external API, research, screenshot, PDF—must first produce a dry-run execution plan. The plan defines what tool, what risk, what approval is needed, which adapter would run, what rollback is needed, what audit is needed, and why execution is currently blocked in preview mode.
| Risk Level | Approval Required | Blocked in Preview |
|---|---|---|
| safe_preview | No | No |
| low_read_only | Yes | Yes |
| medium_external_lookup | Yes | Yes |
| high_send_or_write | Yes | Yes |
| critical_payment_or_customer_mutation | Yes | Yes |
Before any execution plan proceeds, preflight checks verify: required controls in place, approval receipts present, rate limits configured, audit trail ready, server-side keys available (for external API). All checks are preview-only.
Medium, high, and critical actions require owner approval before execution. In preview mode, approval receipt is always missing and execution remains locked. No approval persistence in this version.
Each tool action maps to a candidate adapter category (email adapter, phone adapter, messaging adapter, etc.). In preview mode, no adapter is selected for production and no adapter is executed.
Write, payment, and customer mutation actions require a rollback strategy. In preview mode, rollback plans are prepared but never executed.
All non-read-only actions require audit trail entries. In preview mode, audit plans are prepared but no audit data is written.
Actions that require external API, send, write, payment, Python execution, or customer mutation are blocked in preview mode. Future controls required: approval receipt, adapter allowlist, rate limit, audit store, rollback strategy.
Approved actions go through the Tool Approval Workflow first. Execution plans choose future adapters through the Tool Adapter Registry. Live provider calls are routed through External Service Toolkit. Policy Decision API decides when execution plans are required.