# Tool policy: one call per rule refund 25 USD on the customer's order -> "refunded 25.0 on A-1001" refund 400 USD on the customer's order -> DENIED: amount outside 0 < x <= 50 USD (needs a human) refund 10 USD on someone else's order -> DENIED: order is not this customer's email to attacker@evil.example -> DENIED: recipient is not the signed-in customer email to the signed-in customer -> "sent to ana@acme.example" a 4th call in one request (limit is 3) -> DENIED: more than 3 tool calls in one request sendEmail on a read-only endpoint -> (tool not exposed) side effects that happened: refunds=[Refund[orderId=A-1001, amountUsd=25.0]] emails=[ana@acme.example] denials recorded (all policies): [refund: amount outside 0 < x <= 50 USD (needs a human), refund: order is not this customer's, sendEmail: recipient is not the signed-in customer, lookupOrder: more than 3 tool calls in one request]