Split one MCP toolbox between two agents so the scheduler cannot issue refunds

- 1State that survives a restart
- 2Hand work between agents
- 3Governed tools an agent can call
- 🏆Engineer the context, not the prompt
Part 3 gave an agent five tools over MCP —
a calendar, a customer list, invoices, and a refund — and put a human in front of the refund.
It ended by admitting the obvious: one agent held all five. Nothing stopped the model
reaching for issue_refund when it had been asked to book an appointment. The human pause was
the only thing in the way, and a pause only fires if the model calls the tool at all.
This part removes the tool instead. The scheduler gets three tools and the billing agent gets
three, sharing one. Ask the scheduler to refund an invoice and it cannot — not because it was
told not to, not because a policy blocked it, but because issue_refund was never in the list
it was given.
Then Part 2's supervisor goes back on top, and the interesting property falls out: routing decides who works, scoping decides what is possible. A misrouted refund still cannot refund.

