ADR-009: Data Class of the Chat Tool
- Status
-
Accepted
- Date
-
2026-10-08
- Authors
-
Netresearch DTT GmbH
Context
nr-llm decides per run which tools a model is offered. One axis of that gate
is the trust zone (nr-llm ADR-094): every tool has a data class, the sensitivity
of what it returns into the run, and every provider has a trust zone, which
caps the data class a run against it may collect. A provider without a zone
counts as external, whose ceiling is editor. With
tools., the setting nr-llm ships, a tool above
the ceiling is not offered.
A tool states its class by implementing nr-llm's
Tool; otherwise its group's default applies, and a
group nr-llm does not know resolves to secret, the strictest class.
Start declared nothing, and its group nr_
is not one of nr-llm's groups. The tool therefore ranked as secret-adjacent,
and a run against a provider in the default zone never saw it, even with the
tool and the group switched on.
What the tool returns is small and fixed: on success, the uid of the job row it created, the source URL without query and fragment, and the artifact names; on a refusal, a fixed message. The URL and the artifact names are the caller's own arguments. The content of the source is not returned; the worker fetches and processes it later, outside the run.
Decision
The tool declares editor. The job is an unpublished backend
record, and the result refers to it. nr-llm's editing group is classified
the same way, for the same reason: a writing tool echoes back what it just
set.
Not public. The result names an internal record that nobody
outside the backend can read.
Not higher. source and the classes above it describe the
installation's code, configuration, diagnostics or credentials. The tool
returns none of them.
The class is a property of the code: an administrator cannot relabel it, as nr-llm's interface intends.
Consequences
- ● With the tool and the group switched on, and unless a skill's tool list
- leaves it out, a run against a provider in any trust zone is offered the tool; every call still waits for a person's approval.
- ●
Toolexists in every nr-llm version the extensionData Class Interface - supports, so the declaration needs no version switch.
- ◐ The class covers what the tool returns into the chat run. The generation the
- job starts later sends the source's content to the providers of the extension's own nr-llm configurations; this gate does not see that path.
- ✕ If the result ever returns more, for example generated text or data from
- the source, the class has to be decided again.