Three separate things control what a session can do: context decides what it can reason over, connection authorization decides what the connected provider permits, and tool approval decides whether a protected action runs now. Skills, agent instructions, and workspace settings shape behavior. None of them grant provider access. A skill cannot read your Notion; a connection can.

Before you approve a tool

  • Confirm the named tool matches the task.
  • Check the target: organization, repository, channel, document, or account.
  • Prefer one-time approval while you are still learning a workflow.
  • Deny requests whose purpose or scope is unclear.
  • Verify the result on the provider after a write action.

How approvals work in chat

When a protected action comes up, the session pauses and asks. You can Allow once, Always allow a tool you trust, Always deny this tool, or Deny for this request. Approvals sit in the right rail while the session waits.

Keep the layers separate

  • Modes are the permission contract for the whole session: what Ask, Plan, and Agent may change.
  • Chat and agents shows approvals in the flow of a session.
  • Modes defines what each mode may change.