> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usehenry.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Tool permissions

> Decide, tool by tool, whether Henry runs it automatically or asks first.

Every tool a connection provides has a permission. Open the connected account and go to the **Tools** tab.

## The settings

| Setting                  | What it means                                                      |
| ------------------------ | ------------------------------------------------------------------ |
| **Run automatically**    | Henry uses the tool whenever it is the right thing to do. No card. |
| **Ask for confirmation** | Henry stages a confirmation card and waits for your Confirm.       |
| Off                      | Henry cannot see or use the tool.                                  |

Tools are labeled **Read** or **Write**. Reads default to running automatically. Writes default to asking for confirmation. Anything that spends money always asks, regardless of this setting.

## Changing permissions from a card

You do not need to visit the Tools tab. Every confirmation card offers an "always allow" choice:

* **Confirm + always allow this tool** sets that one tool to Run automatically.
* **Confirm + always allow this integration** sets every tool on that connection to Run automatically.

In the web app the buttons are **Always allow** and **Approve all & always allow**.

## Whose setting is it?

Tool permissions belong to the connection, so they apply to everyone who can use that connection. On a team connection, an admin's choice affects the whole team. Per-person control is done with access levels on the **Access** tab: give someone **Read-only** and Henry uses only the read tools for them, whatever the write tools are set to.

## Tasks are approved separately

Scheduled tasks do not use these settings at run time. When you activate a task, you approve the specific write tools it will use, once. See [Activating and running tasks](/user-guide/tasks/activating-and-running).

## Workspace policy

Admins control who may connect and edit integrations in **Settings → Permissions → Teammate integration permissions**:

* **Connect new integrations**. When off, only admins can connect integrations.
* **Edit other people's integrations**. When off, teammates can only edit integrations they set up.
