
The three permission levels
Each tool on each agent is set to one of three values:
The “Ask” approval appears inline in the chat with a risk-level badge, and you
can expand the card to see the exact tool input before approving. A pending
approval waits as long as you need — there’s no countdown or auto-deny — and the
agent can’t continue that conversation until you allow or deny it (only one
approval is pending at a time). Allowing resumes the agent right where it
paused; denying lets it explain and carry on. Starting a new chat cancels a
pending approval.
Finding the permissions UI
- Open the agent’s detail page.
- Go to the Tools tab.
- Tools are grouped by category (for example, Contacts, Messages, Tasks). Expand a category to see its tools, each with a three-way button.
How defaults work
When you create an agent, it inherits the regular-user baseline permissions for the organization. Tools considered sensitive default to Ask; lower-risk tools default to Allow. Your overrides are stored sparsely — only the tools where you deviate from the default are persisted. If the default shifts later (for example, we promote a new tool from risky to routine), agents inherit the new default unless you had explicitly overridden that tool.Risk levels
Tool approval cards display a risk badge (low / medium / high) to help you decide quickly. Use your judgment: a low-risk tool misused is rarely damaging, a high-risk tool might send email from your domain or spend money.Next steps
Chat with an agent
See approvals in action
Agent conversations
Review past approvals and denials