PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Spring AI supplies the building blocks for a production agent, not a complete safety policy. In Spring AI 2.0.1, a typical agent uses ChatClient and its advisor chain to manage tool calls: the model requests an action, application code executes the matching tool, and the result goes back to the model. Your application still owns authorization, input validation, approval rules, evaluation, and operational controls.
How do I build an AI agent with Spring AI?
Start with a narrowly scoped task and a small set of application-defined tools. In Spring AI 2.0.1, ChatClient composes tool calling through an advisor chain. ToolCallingAdvisor drives the tool-call loop, while ToolCallingManager locates and executes the application’s callbacks.
- The application sends the user’s request and available tool definitions to the model.
- The model either returns an answer or requests a tool by name with arguments.
- The application-side manager finds and executes the corresponding callback.
- The tool result is added to the conversation and returned to the model. The loop continues until the model responds without another tool request.
The model can propose a tool call, but it does not directly access the API behind that tool. Execution remains in the application, where trusted code can validate the request and apply policy. That boundary is useful, but it does not make a tool safe by itself.
Choose the loop that fits your application
| Approach | What it gives you | What your application must handle |
|---|---|---|
ChatClient with the advisor loop |
A composable, framework-managed tool-calling path that can work with advisors. | Tool design, authorization, validation, policy, and operational safeguards. |
Manually driven ChatModel loop |
Explicit control for a custom orchestrator or specialized flow. | Detecting tool requests, executing tools, returning results, and managing loop termination yourself. Calling ChatModel alone does not automatically execute a returned tool request. |
Place advisors with the loop in mind
Advisor order affects whether behavior runs once around a user request or again on each tool iteration. A memory advisor outside the loop sees the final user and assistant messages, not the intermediate tool request and response messages. Put memory inside the loop if the full tool transcript must be retained, and use a repository that supports those message types. Spring AI 2.0 documentation lists in-memory, Redis, and Neo4j repositories as supporting the full message set.
#1 Best Overall
This placement is a design choice: keeping memory outside the loop can simplify storage requirements, while retaining intermediate messages gives later turns a more complete record of the agent’s work.
How do I let an agent call tools safely?
Treat tool definitions as capabilities granted by the application, not as permissions the model can grant itself. Keep tools narrow and enforce authorization and input validation inside the tool implementation or a trusted service boundary. Model-generated arguments are untrusted requests; check them against the current user’s identity, permissions, and the state of the resource before acting.
Bound the tool-call loop
Spring AI 2.0.1 documents default per-turn limits of 40 calls per tool and 150 total tool calls. These are framework configuration defaults, not performance measurements or a guarantee that a workload is safe. They can be configured through the spring.ai.tools.limits.* properties and can be disabled. Set and review explicit limits for the application rather than assuming defaults match its risk or workload.
Keep dynamic tool resolution narrow
Name-based resolver fallback is disabled by default. Enabling it can make tools exposed by a resolver executable when the model names them, including tools with destructive or higher-risk effects. Prefer request-scoped tools where practical, and restrict resolver contents so that a model cannot reach capabilities irrelevant to the current task.
Decide how tool failures are handled
Spring AI’s tool-calling path supports choices about whether a tool error is returned to the model or thrown for the caller to handle. Make that choice deliberately by risk class. Returning every operational failure to the model can invite it to reinterpret or retry an action; handling the failure in application code can preserve a clear boundary for authorization denials, outages, and invalid input.
How can I require human approval before a tool runs?
A custom ToolCallingAdvisor can provide a hook to pause before a destructive tool executes. Spring AI documents this as a use case for customizing the loop. The approval policy and workflow remain application responsibilities.
- Propose: The model requests an action and supplies arguments.
- Validate: The application checks argument shape, resource state, and the current user’s authorization.
- Pause when policy requires it: Present the proposed action to an authorized reviewer before execution.
- Execute only after approval: Call the tool with the validated arguments only if the required approval is recorded.
- Record and resume: Audit the decision and result, then return only the minimum result the agent needs to continue.
This pattern adds review latency and operational work, but creates a deliberate checkpoint before consequential actions. Define who can approve, how long a request remains valid, what happens on timeout or rejection, and how the conversation resumes. Do not treat a model’s claim that approval was granted as evidence; the application must verify the approval through its own trusted process.
Recommended Free Tools
How do I evaluate an AI agent’s answers?
Evaluate the system’s behavior, not just whether a final response sounds plausible. Spring AI defines an Evaluator interface that receives an evaluation request containing the original user text, contextual data, and generated response. Its examples include RelevancyEvaluator, which checks alignment with the query and supplied context, and FactCheckingEvaluator, which checks whether a claim is logically supported by that context.
A model-based evaluator can help automate checks, but a passing score is not proof of truth. For consequential decisions, retain human review and establish what evidence is sufficient for acceptance.
Build a task-specific evaluation set
Include cases that exercise the entire agent path, not just ordinary successful answers:
- Whether the agent selects the expected tool, or correctly answers without calling one.
- Valid, malformed, incomplete, and out-of-range tool arguments.
- Authorization denials and requests for actions requiring human approval.
- Relevant and irrelevant retrieved context, plus claims unsupported by that context.
- Tool errors, timeouts, exhausted call limits, and escalation cases.
Run the set when changing the model, prompt, tool definitions, or advisor order. Track regressions in tool selection, argument quality, evidence use, failure handling, and escalation rather than relying on a single aggregate pass rate.
Free tools Windows power users keep installed
One-click scans. No signup required.
Use an LLM judge carefully
Spring AI’s LLM-as-judge guidance recommends separating the generation and evaluation models to reduce bias, using deterministic evaluation settings, and giving the evaluator an integer rating scale with few-shot examples. These choices can make assessments more consistent, but they do not remove the need to calibrate the evaluator against human judgments.
Best Value
Recursive evaluation that retries an answer based on a rating threshold needs a retry limit and a termination condition. It can add model calls and cost, and advisor order matters. The cited guide discusses recursive advisors in a Spring AI 1.1.0-M4+ context as experimental and non-streaming there; do not assume that version-specific status describes Spring AI 2.0.1. Check the exact release documentation before adopting that pattern.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How do I trace Spring AI tool calls in production?
Spring AI builds on Spring observability and emits Micrometer observations and tracing for core operations, including ChatClient and its advisors, ChatModel, embedding and image models, vector stores, and tool calls. Tool observations can include tool name and definition metadata, execution duration, and tracing context when a tracer is available.
Start with metadata, latency, and failures
Useful operational signals include request and tool latency, errors, limit-exceeded events, model or token usage where supported, advisor behavior, and how often the agent escalates. Confirm the exact metrics and provider instrumentation available for the Spring AI release and integrations you deploy; coverage is not necessarily identical across providers.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesMake content capture an explicit privacy decision
Prompt and completion content are excluded by default because they may be large or sensitive. Tool arguments and results are also excluded by default. Enabling content capture can expose personal, confidential, or otherwise sensitive data in telemetry systems. Begin with metadata and performance signals; enable content only under an approved policy that specifies access controls, redaction, and retention.
Which production choices should I make explicitly?
| Choice | Trade-off | When it fits |
|---|---|---|
| Memory outside the tool loop | Persists final user and assistant messages without requiring storage of intermediate tool messages. | When the conversation does not need the full tool transcript in later turns. |
| Memory inside the tool loop | Can retain tool requests and responses; requires a repository that supports those message types. | When later reasoning or audit workflows need the full exchange. |
| Automatic tool execution | Less review overhead, but actions proceed without a human checkpoint. | For low-risk, reversible actions covered by application authorization and validation. |
| Approval before execution | Adds latency and reviewer effort while creating a policy checkpoint for consequential actions. | For destructive, externally visible, or otherwise high-impact actions. |
| Metadata-only observations | Provides operational timing and tool identity without recording prompt, completion, or tool content by default. | A prudent baseline when content is sensitive or not needed for routine troubleshooting. |
| Content capture | Can provide more debugging context but increases exposure of sensitive data. | Only when access, retention, and redaction are approved and controlled. |
| Single-model evaluation | Simpler to operate, but generation and judging can share biases. | For lower-stakes workflows or an initial evaluation setup with human calibration. |
| Separate judge model | Can reduce shared bias, while adding another model configuration to calibrate and operate. | When evaluation quality justifies the additional complexity and human oversight remains available. |
Production readiness is an application-level property, not a switch in Spring AI. The framework provides the loop, extension points, limits, evaluators, and observability mechanisms; teams must choose and test the policy around them. The Spring AI 2.0.1 references are version-specific, so verify API names, defaults, and provider support against the release actually deployed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

