FitWhen to use it — and when not
Use it when
- Assistants that query data or call APIs
- MCP / plugin ecosystems where tools come from third parties
- Any tool that writes, sends or spends
Skip it when
- Showing every internal helper call — group trivial ones
AnatomyThe parts of the pattern
- Collapsed summary"Ran query_db · 0.8 s" — one line per call.
- Expandable detailArguments and a readable result.
- Permission promptFor write or external tools: allow once, always, deny.
- Answer linkNumbers in the answer trace back to a call.
GuidelinesDo & don’t
Do
- Collapse by default, expand on click.
- Ask before tools that write or leave the product.
- Show the arguments the model actually sent.
Don’t
- Hide tool calls entirely in an analytics product.
- Ask permission for read-only lookups every time.
- Show stack traces as the result.
In the wildReal-world examples
ClaudeChatGPT ("searched 5 sites")Cursor agentClaude Code
Products named for reference only — no affiliation, and the demo above is an original illustration, not a copy of their UI.
For engineersImplementation notes
- Render tool calls from the same message stream as text (tool_use / tool_result blocks), not a side channel.
- Keep a per-tool policy table: auto, ask, deny — editable by the user or admin.
- Truncate large results for display but keep the full payload for audit.