Skip to main content
Open an agent’s Tools tab to choose how it reads, writes, and deletes each resource. Each action lists the tools it affects; actions no tool uses are not shown.

Change permissions

  1. Open Agents and select an agent.
  2. Select Tools.
  3. Find the resource and choose Allow, Ask, or Deny for its action.
  4. Click Save changes.
Tools sharing a resource action always share its setting. For example, changing contacts.write changes both createContact and updateContact.

Child resources

A child without an explicit setting inherits its parent’s permissions. This also applies to sensitive actions such as invoice sending and domain purchases. The tool list shows each tool’s effective setting. Editing a child sets all three actions to their current values, then changes the action you selected. Later parent edits keep that child’s explicit settings. Click Inherit from parent to remove a child override. If the child has its own overrides below it, reset those first. Click Remove override to remove a root setting and deny its actions. Remove its child overrides first. Other resources keep their settings.

Defaults and reset

New agents start with the default agent permissions: reads and invoice draft writes are allowed, while most other changes request approval. Your business role does not choose the agent’s permissions. Saved permissions keep their values when defaults change. A new resource with no permitted parent starts denied. New child resources inherit their parent. Click Reset all to defaults, then Save changes, to apply the current agent defaults. Click Discard to restore your last saved settings.

Approvals and other connections

In chat, expand an approval card to review the input, then click Approve or Deny. One approval can wait in each conversation, without a countdown. Return to that conversation to respond. MCP connections and automations use only actions set to Allow; they cannot ask you for approval. Permission changes apply to the next chat turn, MCP request, or automation run. Work already in progress keeps its starting permissions.
Last modified on September 12, 2026