> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Tool permissions

> Choose whether Connie runs a tool on its own, asks you first, or can't use it at all — and why Connie sometimes asks before acting.

Every tool has a **Permission** that decides what happens when Connie wants to use it: run straight away, show you an approval card first, or never run it. Workspace owners and admins set it per tool. When nobody has chosen, Connie follows sensible defaults: it asks before anything that sends, deletes, spends credits on a built-in tool, or touches a very large number of records.

**Where:** left sidebar → **Tools** → open a tool → **Endpoints** tab · `https://connie.ai/<workspace-id>/tools`

## The three settings

The labels differ slightly between built-in tools and app actions, but they mean the same thing:

| Built-in and workspace tools | App actions (Gmail, Slack, HubSpot…) | What happens |
| - | - | - |
| **Always allow** | **Always allow** | "Connie AI chat can run it without asking." |
| **Ask before running** | **Needs approval** | "Connie shows an Allow / Deny card before it runs." |
| **Disabled** | **Block** | "Connie AI chat and MCP cannot run it." |

## When Connie asks by default

If no one in your workspace has chosen a setting for a tool, Connie decides based on what the tool does:

**Connie asks first for:**

* **Sending or posting to people** — emails, LinkedIn, WhatsApp or Slack messages, posts.
* **Unusual changes in another app.** Everyday changes in your connected apps that don't contact anyone (creating a record in your CRM, a note, a task or a spreadsheet row) run without asking. Other changes in connected apps ask first.
* **Deletes** — deleting records, or a whole workflow or list.
* **Built-in tools that cost credits** — for example enrichment, SEO or scraping tools. Allowing one on the card allows that tool for the rest of the chat.
* **Very large runs** — anything that would touch more than 1,000 records.
* **Tools whose effect or cost Connie can't verify.**

**Connie runs without asking:**

* Free tools that only read data.
* Changes inside your workspace, like adding a record to a list or filling in fields on your Records.
* Removing a step or branch from a workflow, or a field from a list (that's how you edit them).
* App actions that don't send to anyone. App actions never ask *because of their price* (usually 1 credit), only because of what they do.

An explicit setting always wins, in either direction: **Always allow** stops the card even for a send or a paid tool, and **Ask before running** adds one even for a free read. **Disabled** beats everything.

<Note>
  On an app's **Endpoints** tab, the switch shows **Always allow** when nobody has chosen a setting yet — but by the default rules above, actions that send or post (and some other changes in other apps) still ask before running. To stop the prompt for one of those actions, an owner or admin must explicitly click **Always allow** on that endpoint. That saves the choice, and Connie stops asking.
</Note>

## Change a tool's permission

You must be a workspace **owner** or **admin**. Everyone else sees "Only workspace owners and admins can change this."

<Tabs>
  <Tab title="Built-in or workspace tool">
    <Steps>
      <Step title="Open the tool">
        Tools → search for the tool → click it. Workspace tools are on the **Workspace** tab.
      </Step>

      <Step title="Find Permission">
        On the **Endpoints** tab, expand the endpoint. The **Permission** section is at the bottom. The current default has a **Default** tag.
      </Step>

      <Step title="Choose a setting">
        Click **Always allow**, **Ask before running** or **Disabled**. It saves straight away.
      </Step>

      <Step title="Confirm if asked">
        If the tool can change data, send outside Connie, delete or cost credits, choosing **Always allow** opens "Let Connie run this without asking?". It lists what the tool can do and says "Future AI-chat runs will execute without asking for confirmation. You can change this later." Click **Always allow** to confirm, or **Cancel**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="App action">
    <Steps>
      <Step title="Open the app">
        Tools → click the app (for example Gmail).
      </Step>

      <Step title="Find the action">
        On the **Endpoints** tab, each action has a three-icon switch on the right: **Always allow**, **Needs approval**, **Block**.
      </Step>

      <Step title="Click a setting">
        It saves straight away. The switch is dimmed until the app has a connected account ("Connect an account to access these tools").
      </Step>
    </Steps>
  </Tab>
</Tabs>

### What the badges mean

The **Permission** section on a built-in tool shows badges that explain its default:

| Badge | Meaning |
| - | - |
| **Read** | Only reads data. |
| **Changes data** | Changes data in your workspace. |
| **Sends externally** | Sends data outside Connie. |
| **Deletes** | Permanently removes or overwrites data. |
| **Costs N credits** / **Costs up to N credits** | Credit price per call. |
| **Cost unknown** | No established price. |
| **External provider may bill** | The service on the other end may charge you separately. |
| **External billing unknown** | Not known whether the other service charges. |
| **Needs a connected account** | Uses one of your connected accounts (for example your mailbox). |
| **Account requirement unknown** | Not known whether an account is needed. |

After you set **Always allow** on a tool that can change, send, delete or spend, an amber line on the tool reads "Connie runs this without asking." so teammates know why nothing asks.

## Approving a tool in chat

When a tool needs approval, Connie shows an approval card in the chat before running it. What you can do depends on the tool:

* **Paid tools:** **Allow** runs the call and allows that tool for the rest of the chat. The arrow next to it opens **Allow in this chat**, **Always allow** (owners and admins only — saves the setting for the whole workspace) and **Disable this tool**.
* **Sends and deletes:** one button named for the action, such as **Approve & send** or **Approve & delete**.

See [Approvals in chat](/chat/approvals) for the full card.

## Where the setting applies

* **Chat** — follows all three settings.
* **[Agents](/automations/agents)** — ask for approval on tools set to **Ask before running**, and can't use **Disabled** tools. An agent's own settings can add more approvals, never fewer.
* **AI apps connected through [MCP](/mcp/overview)** (Claude, ChatGPT, Cursor…) — **Disabled** blocks the tool there too. **Always allow** and **Ask before running** only change Connie's own chat: from an AI app, a tool that costs credits or changes data is confirmed in that app's own prompt or on a Connie approval page, whatever this setting says.
* **[Skills](/skills/overview)** — running a skill never skips an approval.
* **Follow-ups after a recorded call** — when Connie acts on its own after a meeting, stricter rules apply and **Always allow** isn't used. See [Meetings](/inbox/meetings).

## Good to know

* Only workspace owners and admins can change permissions. Any member can see them. See [Members and roles](/workspace/members-and-roles).
* Permissions are per tool and per workspace. They apply to everyone in the workspace.
* **Allow in this chat** only lasts for that chat. **Always allow** lasts until someone changes it.
* Approving a paid tool doesn't change its price — you're still charged [credits](/billing/credits) for each call.

## Troubleshooting

<AccordionGroup>
  <Accordion title="Connie asks for approval every time it uses a paid tool">
    **Why:** built-in tools that cost credits ask first by default. **Fix:** on the approval card, choose **Allow in this chat** to stop asking for the rest of that chat. To stop it for good, an owner or admin sets the tool's **Permission** to **Always allow**.
  </Accordion>

  <Accordion title="The app action shows Always allow but Connie still asks before sending">
    **Why:** nobody has saved a setting for that action yet. The switch shows **Always allow** in that case, but actions that send or post to people ask by default. **Fix:** an owner or admin clicks **Always allow** on that endpoint to save the choice.
  </Accordion>

  <Accordion title="I can't change a permission — the options are greyed out">
    **Why:** you're not a workspace owner or admin, or (for app actions) the app has no connected account. **Fix:** ask an admin, or [connect an account](/tools/connect-accounts) first.
  </Accordion>

  <Accordion title="Connie says it can't use a tool, or the tool doesn't run">
    **Why:** the tool is set to **Disabled** (or **Block**). That also blocks it for AI apps connected through MCP. **Fix:** an owner or admin sets it back to **Always allow** or **Ask before running**.
  </Accordion>

  <Accordion title="This action cannot be priced, so it will not be run.">
    **Why:** Connie couldn't work out what the call would cost, so it won't run it even with approval. **Fix:** try again later or ask Connie to use a different tool. If it keeps happening, email [support@connie.ai](mailto:support@connie.ai) with the tool's name.
  </Accordion>

  <Accordion title="Connie ran a tool without asking me">
    **Why:** the tool is free and only reads or changes data inside your workspace, or an admin set it to **Always allow**. **Fix:** if you want a card every time, an admin sets it to **Ask before running**.
  </Accordion>
</AccordionGroup>

## Related

* [Approvals in chat](/chat/approvals) — the approval card and its buttons
* [Tools](/tools/overview) — find a tool and see its price
* [Approvals in automations](/automations/approvals) — approvals for workflows and agents
* [Members and roles](/workspace/members-and-roles) — who is an owner or admin


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.