Most agent bugs I hit are really tool description bugs. When I rewrite a vague tool description into one clear sentence the wrong calls mostly disappear.
Thanks, Brian. That's a useful test: one vague tool description can change which action an agent thinks is allowed. A clear description helps, but I'd still want the identity grant to stop a read or send outside the task's scope. What kind of tool wording made the biggest difference for you?