ADR-009: Data Class of the Chat Tool 

Status

Accepted

Date

2026-10-08

Authors

Netresearch DTT GmbH

Context 

nr-llm decides per run which tools a model is offered. One axis of that gate is the trust zone (nr-llm ADR-094): every tool has a data class, the sensitivity of what it returns into the run, and every provider has a trust zone, which caps the data class a run against it may collect. A provider without a zone counts as externalGlobal, whose ceiling is editorContent. With tools.dataClassEnforcement = enforce, the setting nr-llm ships, a tool above the ceiling is not offered.

A tool states its class by implementing nr-llm's ToolDataClassInterface; otherwise its group's default applies, and a group nr-llm does not know resolves to secretAdjacent, the strictest class. StartRepurposeJobTool declared nothing, and its group nr_repurpose is not one of nr-llm's groups. The tool therefore ranked as secret-adjacent, and a run against a provider in the default zone never saw it, even with the tool and the group switched on.

What the tool returns is small and fixed: on success, the uid of the job row it created, the source URL without query and fragment, and the artifact names; on a refusal, a fixed message. The URL and the artifact names are the caller's own arguments. The content of the source is not returned; the worker fetches and processes it later, outside the run.

Decision 

The tool declares editorContent. The job is an unpublished backend record, and the result refers to it. nr-llm's editing group is classified the same way, for the same reason: a writing tool echoes back what it just set.

Not publicContent. The result names an internal record that nobody outside the backend can read.

Not higher. sourceCode and the classes above it describe the installation's code, configuration, diagnostics or credentials. The tool returns none of them.

The class is a property of the code: an administrator cannot relabel it, as nr-llm's interface intends.

Consequences 

● With the tool and the group switched on, and unless a skill's tool list
leaves it out, a run against a provider in any trust zone is offered the tool; every call still waits for a person's approval.
● ToolDataClassInterface exists in every nr-llm version the extension
supports, so the declaration needs no version switch.
◐ The class covers what the tool returns into the chat run. The generation the
job starts later sends the source's content to the providers of the extension's own nr-llm configurations; this gate does not see that path.
✕ If the result ever returns more, for example generated text or data from
the source, the class has to be decided again.