Configure permissions for your agent
You can now choose how much your agent can do without asking. Set a default for the agent, then change the permissions of individual tools if needed.
Set your agent's permissions
Open the agent configuration and click Permissions. Choose from:
- Allow reads: run tools marked as read-only and ask before other calls.
- Allow all: run tool calls without asking.
- Ask: request approval before each tool call.
- Deny all: block tool calls.
New agents created from the standard template start on Allow all. Existing agents keep their saved permissions.
Set exceptions for individual tools
A tool's own permission overrides the agent default. For example, you can set the agent to Ask but allow a specific search tool to run without approval.
Check these exceptions when changing the default. Setting the agent to Ask won't make a tool ask if that tool is explicitly set to Allow.
On an approval card, leave Always auto-approve unchecked if you only want to approve the current call. Checking it lets that tool run without asking again.
See the agent configuration reference for the permission settings.