Describe what the agent should do, hand it the tools it may use, and set the guardrails for what it may not. No flowchart to maintain, no intent tree to keep pruning as reality changes.
Most teams bolt an agent onto a finished API and spend months writing tool definitions by hand, then discover the model can claim to be anybody. Here, marking a method callable is enough — the platform publishes it, describes it, and injects the identity itself.
list_services → 41 callable methodsget_schema("lead") → 22 fields, 4 requiredcreate("lead", { … }) → lead_9f2aorgId + user ← injected by registry