Toolsets
Toolsets are the calling layer over tools: what agents can call, who adopted what, and what fires in practice. The surface is /ai/agents/toolsets: Tools and toolsets agents can call.
- The agents column is adoption truth: which agents call this tool.
- Last called plus 30-day calls is usage truth. A tool with agents but zero calls is adopted, not used; a tool with no agents is shipped, not adopted. Both gaps are cleanup or enablement work, not mysteries.
- Filter by source, status, no-agents, or never-called to find the gaps. Add tool creates beyond the shipped set.
- Every tool is a capability and a liability. Tools often reach external systems through connector bindings and MCP installs; the tool is only real for the tenant when that chain is verified in-environment.

- The environment tool list is the source of truth. If a system is not listed there, sessions cannot reach it no matter what the registry or catalog suggests.
- Atomic layer and binding rules: Tool registry, Extend a connector. The shipped inventory: Catalog. Treat
/ai/agents/toolsetsas the source of truth for toolset surfaces.

