Skip to main content

Configure permissions for your agent

You can now choose how much your agent can do without asking. Set a default for the agent, then change the permissions of individual tools if needed.

Set your agent's permissions​

Open the agent configuration and click Permissions. Choose from:

  • Allow reads: run tools marked as read-only and ask before other calls.
  • Allow all: run tool calls without asking.
  • Ask: request approval before each tool call.
  • Deny all: block tool calls.

New agents created from the standard template start on Allow all. Existing agents keep their saved permissions.

Set exceptions for individual tools​

A tool's own permission overrides the agent default. For example, you can set the agent to Ask but allow a specific search tool to run without approval.

Check these exceptions when changing the default. Setting the agent to Ask won't make a tool ask if that tool is explicitly set to Allow.

On an approval card, leave Always auto-approve unchecked if you only want to approve the current call. Checking it lets that tool run without asking again.

See the agent configuration reference for the permission settings.