
The three permission levels
Each tool on each agent is set to one of three values:| Level | Icon | Behavior |
|---|---|---|
| Allow | Green check | Agent calls the tool silently — no interruption |
| Ask | Blue question | Agent pauses and requests your approval before calling |
| Deny | Red X | Tool is hidden from the agent entirely |
Finding the permissions UI
- Open the agent’s detail page.
- Go to the Tools tab.
- Tools are grouped by category (for example, Contacts, Messages, Tasks). Expand a category to see its tools, each with a three-way button.
How defaults work
When you create an agent, it inherits the regular-user baseline permissions for the organization. Tools considered sensitive default to Ask; lower-risk tools default to Allow. Your overrides are stored sparsely — only the tools where you deviate from the default are persisted. If the default shifts later (for example, we promote a new tool from risky to routine), agents inherit the new default unless you had explicitly overridden that tool.Risk levels
Tool approval cards display a risk badge (low / medium / high) to help you decide quickly. Use your judgment: a low-risk tool misused is rarely damaging, a high-risk tool might send email from your domain or spend money.Next steps
Chat with an agent
See approvals in action
Agent conversations
Review past approvals and denials