Connection settings control which external accounts and tools an agent can use. Configure them per agent instead of treating a connected workspace account as universal access.
Add an account to the agent
Open the agent’s Connections settings and add the intended provider account. An agent stages one active account per provider. Remove a connection from the agent when it should no longer use that account.
When selecting an account, verify the account name as well as the provider. Access is bound to that exact account.
Choose tool tiers
Reads
Retrieve information without changing the provider.
Actions
Create or update information through the approval flow.
Destructive
Delete or irreversibly change information. These tools are disabled by default and require explicit opt-in.
Unknown or unclassified tools receive restrictive access. Do not broaden access merely to make a failing workflow pass; confirm what the tool does first.
Save and test
Save the policy
Confirm the exact account and enabled tools on the agent, then save the agent.
Test a read
Use a representative read request to verify the selected account and retrieved data.
Test an action
Send a representative action through approval and inspect the proposed account, arguments, and effect.
The tool policy persists when a connection is reauthorized. Reconnecting restores credentials; it does not silently reset the agent’s permissions.