Manage Tools & Connectors
As an administrator, you control which tools your organization's agents can use — and how much freedom users have with each tool.
Native tools and connectors
The Tools page lists every capability available to your organization in one table. A filter above the table narrows what you see.
Filter
What it shows
Your controls
All
Every capability, native and connector together
Whichever controls apply to each row
Native
Tools built into Blockbrain, such as the Code Interpreter or Knowledge Management, including ready-to-use services where Blockbrain provides the connection
Switch each capability on or off for your organization
Connectors
Tools that reach into your own systems through an account your organization connects, such as Excel, Outlook or SharePoint
Switch each connector on or off, plus set a permission level on every individual tool inside it
The rule of thumb: a capability is a connector when your organization connects its own account for it. Everything else is native.
Native tools and connectors
Setting a tool's permission level
Connectors carry your organization's own credentials and can have real side effects — reading mailboxes, editing spreadsheets, sending messages. That is why every individual tool inside a connector has one of three permission levels:
Permission
What it means for your users
Always Allow
The tool works without asking. The agent uses it as needed, with no approval prompts.
Needs Approval
Each time the agent wants to run the tool, the user is asked first and the action only runs once they approve it. Declining stops that action.
Blocked
The tool cannot be used in your organization. Agents will not run it, and users attempting to use it are informed that it is not available.
To change a tool's permission level:
Go to Admin → Agents and open the Connectors tab.
Find the connector you want to govern and open its Tool permissions window, using the gear in the Permissions column.
Under Access, set the level for each tool: Always allow, Needs approval or Blocked.
Changes take effect for all users and all agents in your organization.
Tool Permission levels
Working through a long tool list
A connector can hold dozens of tools, so the Tool permissions window gives you three ways to move faster.
Two groups. Tools are split into Read-only tools, which only look things up, and Write/delete tools, which change, send or remove data.

Tool groups
Set a whole group at once. Each group heading carries its own control, so you can put every read-only tool on Always allow in a single action and then review the write/delete tools one by one.

Bulk settings change
Search. The search box filters the list by tool name.

Reset all Tool permission settings
If you want to start over, Reset all returns every tool in that connector to its default permission. You are asked to confirm first, because any permissions you have customized are lost.
Safe defaults. Tools that write, send or delete data start on Needs Approval. You can set such a tool to Always Allow, but consider it carefully: the agent will then perform those actions without asking the user first.
What your users experience
Always Allow — nothing changes for the user; the tool simply works.
Needs Approval — when the agent is about to run the tool, the conversation pauses and shows an approval request describing the action. The user approves or declines; the agent continues only after an approval.

Tool Approval card
Blocked — the agent does not run the tool, and the user is informed that the tool is not available in your organization. If your users report a tool as "not working", it is worth checking this page first — the tool may simply be blocked by policy.

Example message when the tool is blocked
One exception to Needs approval. Alongside Approve and Decline, the approval request offers Approve all (this session). If a user chooses it, every further tool call in that same conversation runs without asking, including tools you have set to Needs approval. It covers that one conversation only, not the user's other chats, and a new conversation starts asking again. If your organization needs approval to be unskippable, contact your Blockbrain Customer Success Manager to have this turned off.
Where did the Tool Approval tab go?
Tool approval settings previously lived on a separate Tool Approval tab. That tab has been retired: its settings moved to the Connectors tab, where the approval behavior is now set per tool, together with everything else about the tool.
Last updated

