Your agent can only act in apps your organization has authorised, and for sensitive actions it asks first. Approvals happen right in the chat, so you always know what’s about to happen before it does.

The approval card

When the agent wants access it doesn’t have, an approval card appears in the conversation naming exactly what’s being requested. Allow and the agent continues; Deny and it works out another way or tells you it can’t proceed. Nothing runs while a card is waiting on you.

Connecting an app mid-chat

If the task needs an app that isn’t connected at all, the agent asks for the connection itself. Approving opens the app’s own sign-in, and you land back in the chat with the connection made and the task resumed. The connection then belongs to the agent, so it’s there for every future task; manage it any time under Connections.

What the agent can reach

An agent’s toolkit is the sum of its connections plus its built-ins (like reading its skills or creating Agent Automations from a chat). It discovers the right tool for the job as it works, and everything it actually did is visible step by step in the chat, so the record of what happened is always the conversation itself.