본문으로 건너뛰기
← Workshop overview
Chapter 3 of 7
15 min

Separate display commands from data questions

Compare two real requests and understand the allow-list gate that executes only UI_CONTROL.

Question for this chapter

Should “show the zone” and “tell me today’s patrol history” run with the same permission?

Why this matters now

Both requests concern chart operations, but their effects differ. One changes the display; the other queries operational data. Similar wording is not a reason to give both requests the same tools and scope.

Try it

Open the map-control Agent workflow in map_ops. The canvas titles nodes by type—such as LLM, If Else, and Tool Call—rather than by node ID. Use the type and configuration clues below to match the names used in this Workshop to the canvas.

Node IDCanvas labelConfiguration clue
classify_intentLLMruns the intent classifier and outputs intent_type
validate_intentIf Elsecondition contains classify_intent_output.intent_type == 'UI_CONTROL'
lookup_zoneTool Callcalls query_tactical_zone
resolve_coordinatesTool Callcalls query_graphic_overlay
format_parametersCodeassembles longitude, latitude, and scale into control JSON
log_eventActor Callpublishes the audit event on the allowed (True) path
reject_commandTemplatewrites the rejection reason beginning with # Command rejected
log_rejectionActor Callpublishes the audit event on the blocked (False) path
select_event_logCodeselects one event record from the two paths

Inspect the If Else node (validate_intent) after the LLM node (classify_intent).

Predict the path for each request before running it.

Natural-language requestCurrent classification contractAutomatic executionReason
Show Busan Port Entry/Exit Control ZoneUI_CONTROLallowedread-only display control
Tell me today’s patrol historyDATA_QUERYblockedrequires a separate query tool and permission

The current Agent has five labels: UI_CONTROL, DATA_QUERY, SYSTEM_CONFIG, RESTRICTED_ACTION, and NAVIGATION. The If Else node (validate_intent) sends only UI_CONTROL to the Tool Call node (lookup_zone) that calls query_tactical_zone.

Success looks like this

The allowed branch continues through the two Tool Call nodes that call query_tactical_zone and query_graphic_overlay, then the allowed-path Actor Call (log_event). The blocked branch continues through the Template node (reject_command) and blocked-path Actor Call (log_rejection). A blocked request still reaches the audit path.

The flow below shows both paths converging on the same audit record after different handling.

Loading the diagram. Mermaid source:

flowchart LR
    accTitle: Safety gate for a display command and a data question
    accDescr: The Busan port display command is classified as UI CONTROL and reaches zone lookup and coordinate JSON, while the patrol-history question is classified as DATA QUERY and blocked; both requests produce audit events.
    command["Show the zone"] --> classify{Classify intent}
    query["Tell me patrol history"] --> classify
    classify -->|UI_CONTROL| allow[Zone lookup and JSON]
    classify -->|Other| block[Rejection reason]
    allow --> audit[(Audit event)]
    block --> audit

Interpret the result

This is an allow-list. It does not execute everything that is absent from a block-list. It executes only the explicitly allowed UI_CONTROL label. Ambiguous classifications stop under a reject by default policy.

Rejection is not an execution failure. It is a responsibility boundary that routes the request toward a more appropriate tool and permission. The original request and rejection reason still need an audit trail.

Deep dive — the guide and the current Agent have different boundaries

The imported operation_guide describes DATA_QUERY as safe in its general policy table. The current map-control Agent, however, allows only UI_CONTROL in its actual branch condition.

Use the executable Agent definition as the permission source for this Workshop. In production, align the documentation and workflow before granting a broader scope.

Next decision

You have fixed the allowed scope. Next, run an allowed command and a blocked question in one session, then inspect both the coordinate output and audit event.