The default posture is simple: all reads are allowed, all connector writes need your approval, and you can tighten or loosen any individual tool at any time. On top of that sit hard limits that no setting can change — the agent can never send an email, and it can never delete anything. This page is the complete reference.
The Tool Permissions Panel
Under Connectors, open Tool permissions — "Choose when MorningAI is allowed to use these tools." Every tool the agent can use is listed per connector, grouped into Read tools and Write tools, and each one is individually set to one of three levels:
| Setting | What it means |
|---|---|
| Always allow | The tool runs without asking. Default for all read tools. |
| Needs approval | The turn pauses and shows an approval card before the tool runs. Default for all write tools. |
| Blocked | The agent cannot use the tool at all. |
Personal vs Brand Scoping
Permission settings follow the connector's ownership. Personal connectors — Gmail, Google Drive, Google Calendar — carry your settings with you across every brand you work in. Brand connectors — Shopify, Google Analytics, Search Console — share their settings across the whole brand team, so the team's policy applies to everyone consistently.
The Approval Card, Step by Step
When a tool set to "Needs approval" is about to run, the turn pauses and a card appears in the conversation:
- The card says what's being asked: "MorningAI wants to use {Tool} from {Connector}" — for example, Create a draft from Gmail.
- It shows the exact parameters the tool will use — you review precisely what will happen, not a vague summary.
- You choose: Always allow (stop asking for this tool), Allow once, or Deny.
- The card resolves to a record of your decision — "Always allowed", "Allowed once", or "Denied" — and the turn continues (or skips the action).
Hard Limits: Guarantees, Not Settings
Some things aren't permissions you configure — they're capabilities that don't exist. No setting can turn these on:
| Area | Guarantee |
|---|---|
| Gmail | Drafts only. No send, no delete, no archive, no labels — sending is always a human action in Gmail. |
| Google Drive | Create new files only. Never edits or deletes an existing file. |
| Google Calendar | Can create, update, and RSVP with approval — but can never delete an event. |
| Shopify, Analytics, Search Console | Read-only. There are no write tools for these connectors at all. |
| Products and personas | Can create and update, never delete. |
| Social publishing | Agents don't publish to social media from chat. Publishing happens through the composer and calendar, where agent work arrives via Home → Recent Work. |
One behavior worth knowing rather than fearing: when an approved calendar event includes guests, those invitees receive the normal calendar email — standard calendar behavior, shown in the parameters before you approve.
Recommended Setup
- Keep the defaults at first: reads allowed, writes on approval. You'll see exactly what the agent wants to do before it does it.
- Promote trusted, repetitive writes to Always allow from the approval card itself — approve Create a draft a few times and you'll know whether you want to stop being asked.
- Review the panel whenever you add a new connector, not only during initial setup.
Frequently Asked Questions
Do approvals replace permissions? No — they're layers. Permissions define what the agent may attempt; approval cards confirm individual actions at runtime for anything set to "Needs approval".
Can I change a decision later? Yes. "Always allow" choices and every other setting can be changed in the Tool permissions panel at any time.
Whose settings apply to a brand connector? The brand team's shared settings — everyone on the team works under the same policy for Shopify, Analytics, and Search Console.
Next Steps
If you haven't connected anything yet, start with Gmail, Drive, and Calendar — then watch the approval card appear the first time you ask for an email draft.