# Build support agents around resolution, escalation and safe tool use

> A support agent succeeds when it resolves a permitted case correctly or hands it to a human with enough context. KeepRouter can provide model access, scoped keys and request usage evidence; the application must own customer permissions, knowledge freshness, tool execution, escalation rules and resolution measurement. [1](https://developers.openai.com/api/docs/guides/agent-evals) [2](https://platform.claude.com/docs/en/agents-and-tools/tool-use/overview) [3](https://keeprouter.com/api/openapi.json)

_Last reviewed 2026-09-28 · [Editorial review](https://keeprouter.com/editorial-policy#editorial-team)_

## Measure the case, not the cheapest request

A support conversation may contain classification, retrieval, drafting, tool calls and a human handoff. A lower token rate can still cost more per resolved case if it creates extra turns or bad tool decisions. Define a case outcome before comparing models: resolved and verified, correctly escalated, reopened, unsupported answer, or unsafe action. The [cost-per-resolution worksheet](/blog/support-agent-cost-per-resolution) shows how to combine model charges with retries and human review without pretending these are KeepRouter customer results.

## Separate answer generation from account actions

| Work | Safe first release | Gate before expansion |
| --- | --- | --- |
| Answer policy questions | Retrieve approved, dated articles and cite the passage | Sample answers for unsupported claims |
| Check an order or account | Read-only tool with customer authorization | Audit tool arguments and access filters |
| Change an order, credit or subscription | Human confirmation or handoff | Idempotency, permission and reversal tests |
| Escalate | Summarize the attempted path and known facts | Verify that private fields do not leak into a new case |

Anthropic's [tool-use documentation](https://platform.claude.com/docs/en/agents-and-tools/tool-use/overview) distinguishes client tools, which execute in your application, from server tools. A compatible model response does not give KeepRouter authority to execute your business action. Keep the tool runner and approval policy in your service. Use the [agent builder guide](/built-for/agent-builders) for loop and retry boundaries.

## Pick a small model shortlist and test the full path

Choose candidate model IDs and their exact endpoints from the [live catalog](/models). Begin with a redacted set of actual support intents and a separate adversarial set: missing order, conflicting policy, unauthorized user, stale knowledge, and tool timeout. Run the same cases with each candidate. Record completed outcome, escalation correctness, tool arguments, latency distribution, input/output usage and charge. OpenAI's [agent evaluation guide](https://developers.openai.com/api/docs/guides/agent-evals) describes traces that include model calls, tool calls, guardrails and handoffs; use an equivalent trace in your own stack even if the selected model is not an OpenAI model.

## Where the gateway helps and where it stops

Keep a support-service key on the server, allow only evaluated model IDs, and set a spend limit appropriate for repeated conversations. Separate production from evaluation keys. The [usage view](/features/api-observability) can explain model, route, status, token and charge at request level. It cannot prove that a customer was helped, that a refund was justified, or that the retrieved article was current. Join gateway request IDs to your case ID and outcome ledger in your own system, with a retention policy for private data.

Start with answer drafting and human review. Add read-only tools only after permissions pass. Add write actions only after you can test escalation, duplicate delivery and rollback.

## Frequently asked questions

### Does KeepRouter resolve support tickets?

No. It provides model routes and request usage evidence. Your application owns retrieval, tools, case state and human escalation.

### Should a support agent execute account changes directly?

Begin with draft and read-only paths. Test permission, confirmation, idempotency and reversal before any write action.

### What is the right cost metric?

Use cost per verified resolution and cost per correctly escalated case, with model, retry and human-review costs separated.

### Can a gateway request log prove answer quality?

No. Pair request metadata with a case-level evaluation and human-reviewed outcomes.

## Sources reviewed

_Sources last reviewed 2026-09-28_

1. [OpenAI agent evaluation guide](https://developers.openai.com/api/docs/guides/agent-evals)
2. [Anthropic tool use guide](https://platform.claude.com/docs/en/agents-and-tools/tool-use/overview)
3. [KeepRouter OpenAPI](https://keeprouter.com/api/openapi.json)
4. [KeepRouter live model catalog](https://keeprouter.com/models)

## Related guides

- [Support agent cost per resolution: a measurement worksheet](https://keeprouter.com/blog/support-agent-cost-per-resolution.md)
- [agent builders](https://keeprouter.com/built-for/agent-builders.md)
- [API observability](https://keeprouter.com/features/api-observability.md)
- [models](https://keeprouter.com/models.md)
- [How to evaluate an AI gateway: tests, costs and a filled scorecard](https://keeprouter.com/blog/evaluate-ai-gateway.md)

## Evaluate one support intent

Test an approved answer and a correct human escalation with the same scoped model route before adding write tools.

[Create a free key](https://keeprouter.com/login?returnTo=%2Fconsole%2Fkeys%3Fmodel%3Dfree) · [Live models and pricing](https://keeprouter.com/models.md)
