Agents

Agent Permissions and Approvals: The Complete Reference

How you stay in control of MorningAI agents: the default permission posture, the Tool permissions panel, in-chat approval cards, and the hard limits that are guarantees — not settings.

Browse Agents

The default posture is simple: all reads are allowed, all connector writes need your approval, and you can tighten or loosen any individual tool at any time. On top of that sit hard limits that no setting can change — the agent can never send an email, and it can never delete anything. This page is the complete reference.

The Tool Permissions Panel

Under Connectors, open Tool permissions — "Choose when MorningAI is allowed to use these tools." Every tool the agent can use is listed per connector, grouped into Read tools and Write tools, and each one is individually set to one of three levels:

SettingWhat it means
Always allowThe tool runs without asking. Default for all read tools.
Needs approvalThe turn pauses and shows an approval card before the tool runs. Default for all write tools.
BlockedThe agent cannot use the tool at all.

Personal vs Brand Scoping

Permission settings follow the connector's ownership. Personal connectors — Gmail, Google Drive, Google Calendar — carry your settings with you across every brand you work in. Brand connectors — Shopify, Google Analytics, Search Console — share their settings across the whole brand team, so the team's policy applies to everyone consistently.

The Approval Card, Step by Step

When a tool set to "Needs approval" is about to run, the turn pauses and a card appears in the conversation:

  1. The card says what's being asked: "MorningAI wants to use {Tool} from {Connector}" — for example, Create a draft from Gmail.
  2. It shows the exact parameters the tool will use — you review precisely what will happen, not a vague summary.
  3. You choose: Always allow (stop asking for this tool), Allow once, or Deny.
  4. The card resolves to a record of your decision — "Always allowed", "Allowed once", or "Denied" — and the turn continues (or skips the action).

Hard Limits: Guarantees, Not Settings

Some things aren't permissions you configure — they're capabilities that don't exist. No setting can turn these on:

AreaGuarantee
GmailDrafts only. No send, no delete, no archive, no labels — sending is always a human action in Gmail.
Google DriveCreate new files only. Never edits or deletes an existing file.
Google CalendarCan create, update, and RSVP with approval — but can never delete an event.
Shopify, Analytics, Search ConsoleRead-only. There are no write tools for these connectors at all.
Products and personasCan create and update, never delete.
Social publishingAgents don't publish to social media from chat. Publishing happens through the composer and calendar, where agent work arrives via Home → Recent Work.

One behavior worth knowing rather than fearing: when an approved calendar event includes guests, those invitees receive the normal calendar email — standard calendar behavior, shown in the parameters before you approve.

  • Keep the defaults at first: reads allowed, writes on approval. You'll see exactly what the agent wants to do before it does it.
  • Promote trusted, repetitive writes to Always allow from the approval card itself — approve Create a draft a few times and you'll know whether you want to stop being asked.
  • Review the panel whenever you add a new connector, not only during initial setup.

Frequently Asked Questions

Do approvals replace permissions? No — they're layers. Permissions define what the agent may attempt; approval cards confirm individual actions at runtime for anything set to "Needs approval".

Can I change a decision later? Yes. "Always allow" choices and every other setting can be changed in the Tool permissions panel at any time.

Whose settings apply to a brand connector? The brand team's shared settings — everyone on the team works under the same policy for Shopify, Analytics, and Search Console.

Next Steps

If you haven't connected anything yet, start with Gmail, Drive, and Calendar — then watch the approval card appear the first time you ask for an email draft.

Customer Success Team
Customer Success Team

Writers

The MorningAI Customer Success team is here to help you win. Whether you're stuck, scaling, or just getting started, we move fast, solve problems, and make sure nothing slows you down.

Was this article helpful?

See it live on your brand

Docs are a start — book a demo and we'll show you MorningAI running on your own products.

Related Articles