Skip to content

Connection access and approvals

Understand how account access, tool permissions, and human review work together.

AI Agent uses two complementary controls for connected services: connection access limits what an agent may use, while approvals let a person review proposed external changes before execution.

How the controls work together

Limit available access

Assign only the connected accounts and tools needed for the agent’s role.

Let the agent prepare work

The agent can use its allowed reads and propose an allowed external change within its instructions.

Review the exact proposal

When approval is required, inspect the provider, account, action, and displayed arguments before deciding.

Execute or stop

Approval allows that proposal to execute; rejection stops it. Neither decision silently broadens the agent’s access.

Review access over time

Recheck connection access when an agent’s role changes, a teammate leaves, an account is replaced, or a workflow begins making different kinds of changes.

Put it into practice

Navigation