---
title: "ADR-009: Data Class of the Chat Tool"
manual: "Content Repurpose"
version: "0.11"
permalink: "https://docs.typo3.org/permalink/netresearch/nr-repurpose:adr-009@0.11"
source: "Adr/Adr009ChatToolDataClass.rst"
rendered: "2026-10-08T11:54:23+00:00"
---

# ADR-009: Data Class of the Chat Tool {#adr-009}

-   *Status:* Accepted
-   *Date:* 2026-10-08
-   *Authors:* Netresearch DTT GmbH

## Context {#adr-009-context}

nr-llm decides per run which tools a model is offered. One axis of that gate
is the trust zone (nr-llm ADR-094): every tool has a data class, the sensitivity
of what it returns into the run, and every provider has a trust zone, which
caps the data class a run against it may collect. A provider without a zone
counts as `externalGlobal`, whose ceiling is `editorContent`. With
`tools.dataClassEnforcement = enforce`, the setting nr-llm ships, a tool above
the ceiling is not offered.

A tool states its class by implementing nr-llm's
`ToolDataClassInterface`; otherwise its group's default applies, and a
group nr-llm does not know resolves to `secretAdjacent`, the strictest class.
`StartRepurposeJobTool` declared nothing, and its group `nr_repurpose`
is not one of nr-llm's groups. The tool therefore ranked as secret-adjacent,
and a run against a provider in the default zone never saw it, even with the
tool and the group switched on.

What the tool returns is small and fixed: on success, the uid of the job row it
created, the source URL without query and fragment, and the artifact names; on
a refusal, a fixed message. The URL and the artifact names are the caller's own
arguments. The content of the source is not returned; the worker fetches and
processes it later, outside the run.

## Decision {#adr-009-decision}

**The tool declares** `editorContent`. The job is an unpublished backend
record, and the result refers to it. nr-llm's `editing` group is classified
the same way, for the same reason: a writing tool echoes back what it just
set.

**Not** `publicContent`. The result names an internal record that nobody
outside the backend can read.

**Not higher.** `sourceCode` and the classes above it describe the
installation's code, configuration, diagnostics or credentials. The tool
returns none of them.

The class is a property of the code: an administrator cannot relabel it, as
nr-llm's interface intends.

## Consequences {#adr-009-consequences}

-   **●  With the tool and the group switched on, and unless a skill's tool list**

    leaves it out, a run against a provider in any trust zone is offered the
    tool; every call still waits for a person's approval.

-   **●  `ToolDataClassInterface` exists in every nr-llm version the extension**

    supports, so the declaration needs no version switch.

-   **◐  The class covers what the tool returns into the chat run. The generation the**

    job starts later sends the source's content to the providers of the
    extension's own nr-llm configurations; this gate does not see that path.

-   **✕  If the result ever returns more, for example generated text or data from**

    the source, the class has to be decided again.
