Permissions and approvals

Work with agentsEnglish· 2 min read· Updated October 01, 2026

Control what an agent may prepare, request and execute.

Connection is not permission

A connection identifies a service the agent can potentially use. Tool permissions decide which actions are allowed, require approval or are disabled. The agent’s autonomy setting is another limit; it does not bypass the tool’s rules.

For a new task, start with a setting that lets you review sensitive actions. Payments still require a signature. An action that sends information outside the workspace may require approval even when the connected account is available.

Review an approval

  1. Read the service, action, target and proposed arguments.
  2. Check that the action matches the request and contains no unintended recipient or data.
  3. Approve only the action you want performed, or reject it and explain the correction.
  4. Check the execution outcome after approval; approval alone is not proof that the provider completed the action.

Understand a paused task

Awaiting approval means the action is waiting. A rejected action should not be worked around with another tool or account. If the result is uncertain after a network failure, inspect the connected service before requesting a repeat to avoid duplicates.

To change the allowed behavior, update the agent or tool configuration deliberately. Do not paste a secret into the conversation as a substitute for a missing connection.

Choose the permission setting in the agent sheet

Execute lets permitted actions run directly. Ask requests approval before an action with an effect. Signature waits for your signature on those actions. Block prevents external tool actions, including reads; the assistant can still respond in text.

In the other settings, read-only operations and calculations can run without a signature. Payments still require a payment signature, and explicitly disabled tools stay disabled. If you enable reactions to events, review the permission choice again: the interface requires Execute for this behavior.

Check who can approve

Project owners and editors can trigger executions and approve ordinary actions. Viewers can inspect the work but cannot launch or sign it. Connecting or revoking services is reserved for the owner.

Payment signatures are owner-only by default. The owner can explicitly allow editors to sign payments in the project rights settings. An agent’s permission setting does not grant a collaborator a role they do not have.

Next steps

AI agents
Did this guide help?
Please leave passwords and private account details out of your feedback.