Return this from a can_use_tool callback (see Permissions) to stop the
run before the tool executes and save the pending call to disk. Approve or
deny it later, possibly from another R process, with
agent$resume_approval(); approval_read() shows what is waiting.
Details
The agent needs an approval_dir, and the tool must be registered with
convert = FALSE, so its function receives the raw JSON arguments. Tool
results should be strings, JSON from jsonlite::toJSON(), or ellmer content
objects. Inputs or results shaped like a list with version, class and
props fields are rejected, because ellmer would read them back as
serialized objects.