I used a project called toolgate to autoapprove "safe" tool calls but request permission on riskier calls declaratively. But there's so many unnecessary tool permission requests
I would recommend anyone that has desire to provide stricter boundaries to agents to give it a try - while remembering that a motivated agent would probably be able to escape it :)