# Tool policy: one call per rule

refund 25 USD on the customer's order     -> "refunded 25.0 on A-1001"
refund 400 USD on the customer's order    -> DENIED: amount outside 0 < x <= 50 USD (needs a human)
refund 10 USD on someone else's order     -> DENIED: order is not this customer's
email to attacker@evil.example            -> DENIED: recipient is not the signed-in customer
email to the signed-in customer           -> "sent to ana@acme.example"
a 4th call in one request (limit is 3)    -> DENIED: more than 3 tool calls in one request
sendEmail on a read-only endpoint         -> (tool not exposed)

side effects that happened: refunds=[Refund[orderId=A-1001, amountUsd=25.0]] emails=[ana@acme.example]
denials recorded (all policies): [refund: amount outside 0 < x <= 50 USD (needs a human), refund: order is not this customer's, sendEmail: recipient is not the signed-in customer, lookupOrder: more than 3 tool calls in one request]
