> For the complete documentation index, see [llms.txt](https://docs.blockbrain.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blockbrain.ai/for-admins/manage-tools-and-connectors.md).

# Manage Tools & Connectors

As an administrator, you control which tools your organization's agents can use — and how much freedom users have with each tool.

### Native tools and connectors <a href="#native-tools-and-connectors" id="native-tools-and-connectors"></a>

The Tools page lists every capability available to your organization in one table. A filter above the table narrows what you see.

| Filter         | What it shows                                                                                                                                               | Your controls                                                                                     |
| -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- |
| **All**        | Every capability, native and connector together                                                                                                             | Whichever controls apply to each row                                                              |
| **Native**     | Tools built into Blockbrain, such as the Code Interpreter or Knowledge Management, including ready-to-use services where Blockbrain provides the connection | Switch each capability on or off for your organization                                            |
| **Connectors** | Tools that reach into your own systems through an account your organization connects, such as Excel, Outlook or SharePoint                                  | Switch each connector on or off, *plus* set a permission level on every individual tool inside it |

The rule of thumb: a capability is a **connector** when your organization connects its own account for it. Everything else is **native**.

{% embed url="<https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2F81LsqJmil3tStz3NUFxj%2Fnative-and-connector.mp4?alt=media&token=bd91961a-0d9a-464c-acb3-77fa76dd3126>" %}

<p align="center"><sub><em>Native tools and connectors</em></sub></p>

### Setting a tool's permission level <a href="#setting-a-tools-permission-level" id="setting-a-tools-permission-level"></a>

Connectors carry your organization's own credentials and can have real side effects — reading mailboxes, editing spreadsheets, sending messages. That is why every individual tool inside a connector has one of three permission levels:

| Permission         | What it means for your users                                                                                                                   |
| ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| **Always Allow**   | The tool works without asking. The agent uses it as needed, with no approval prompts.                                                          |
| **Needs Approval** | Each time the agent wants to run the tool, the user is asked first and the action only runs once they approve it. Declining stops that action. |
| **Blocked**        | The tool cannot be used in your organization. Agents will not run it, and users attempting to use it are informed that it is not available.    |

To change a tool's permission level:

1. Go to **Admin → Agents** and open the **Connectors** tab.
2. Find the connector you want to govern and open its **Tool permissions** window, using the gear in the **Permissions** column.
3. Under **Access**, set the level for each tool: **Always allow**, **Needs approval** or **Blocked**.

Changes take effect for all users and all agents in your organization.

{% embed url="<https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2FqWZlejI4Vn87RRj5PhBf%2Fthree-permission-settings.mp4?alt=media&token=b3c60b48-601f-40dc-8ad2-c1f01fb6f38a>" %}

<p align="center"><sub><em>Tool Permission levels</em></sub></p>

### Working through a long tool list <a href="#working-through-a-long-tool-list" id="working-through-a-long-tool-list"></a>

A connector can hold dozens of tools, so the **Tool permissions** window gives you three ways to move faster.

* **Two groups**. Tools are split into **Read-only** tools, which only look things up, and **Write/delete** tools, which change, send or remove data.

<figure><img src="https://3232460952-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2FsLJ0RIQCg90vLK4CEqty%2Fimage.png?alt=media&amp;token=0d4317b2-0e84-4629-b98b-433f990052f7" alt=""><figcaption></figcaption></figure>

<p align="center"><sub><em>Tool groups</em></sub></p>

* **Set a whole group at once**. Each group heading carries its own control, so you can put every read-only tool on **Always allow** in a single action and then review the write/delete tools one by one.

<figure><img src="https://3232460952-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2FyGEbruWqOkJQd91ceXz1%2FBildschirmfoto%202026-08-20%20um%2012.52.42.png?alt=media&amp;token=e19f21df-9cae-47a5-922c-b62487ce0085" alt=""><figcaption></figcaption></figure>

<p align="center"><sub><em>Bulk settings change</em></sub></p>

* **Search**. The search box filters the list by tool name.

<figure><img src="https://3232460952-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2FOwXaWpijuiHtpiXoC5fp%2Fimage.png?alt=media&amp;token=effa2725-8576-44c6-b529-51114b6a543c" alt=""><figcaption></figcaption></figure>

<p align="center"><sub><em>Reset all Tool permission settings</em></sub></p>

If you want to start over, **Reset all** returns every tool in that connector to its default permission. You are asked to confirm first, because any permissions you have customized are lost.

**Safe defaults.** Tools that write, send or delete data start on **Needs Approval**. You can set such a tool to **Always Allow**, but consider it carefully: the agent will then perform those actions without asking the user first.

### What your users experience <a href="#what-your-users-experience" id="what-your-users-experience"></a>

* **Always Allow** — nothing changes for the user; the tool simply works.
* **Needs Approval** — when the agent is about to run the tool, the conversation pauses and shows an approval request describing the action. The user approves or declines; the agent continues only after an approval.

<figure><img src="https://3232460952-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2FuKEGhYIt8HosIQTNWuoc%2Fimage.png?alt=media&amp;token=898605cf-78c5-4e4a-9fee-35b5fd6592b8" alt=""><figcaption></figcaption></figure>

<p align="center"><sub><em>Tool Approval card</em></sub></p>

* **Blocked** — the agent does not run the tool, and the user is informed that the tool is not available in your organization. If your users report a tool as "not working", it is worth checking this page first — the tool may simply be blocked by policy.

<figure><img src="https://3232460952-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIabFtGTeQzwfWCzp8vd6%2Fuploads%2F07VIxDSZR7b9zoQEK7fJ%2Fimage.png?alt=media&amp;token=4a5b4664-6e3c-4ac8-800d-a28d80bc13b5" alt=""><figcaption></figcaption></figure>

<p align="center"><sub><em>Example message when the tool is blocked</em></sub></p>

**One exception to Needs approval**. Alongside Approve and Decline, the approval request offers **Approve all (this session)**. If a user chooses it, every further tool call in that same conversation runs without asking, including tools you have set to Needs approval. It covers that one conversation only, not the user's other chats, and a new conversation starts asking again. If your organization needs approval to be unskippable, contact your **Blockbrain Customer Success Manager** to have this turned off.

### Where did the Tool Approval tab go? <a href="#where-did-the-tool-approval-tab-go" id="where-did-the-tool-approval-tab-go"></a>

Tool approval settings previously lived on a separate **Tool Approval** tab. That tab has been retired: its settings moved to the **Connectors** tab, where the approval behavior is now set per tool, together with everything else about the tool.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.blockbrain.ai/for-admins/manage-tools-and-connectors.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
