Permission is set on each individual tool an integration offers, not on the integration as a whole. This lets you allow ServiceNow reads to run freely while ServiceNow writes wait for approval, and lets you make a destructive call unavailable entirely.
The Three Permission Levels
Tool permissions are set when enabling an integration and can be changed.
Level | What LuumenAI Can Do | Typical Use |
Full access | Run the tool without asking. The call still appears live in the conversation and lands in the audit log. | Listing, searching, reading a record, or checking status |
Ask for approval | Propose the call and wait. The conversation shows the exact call, the evidence, and a risk level; the tool runs only when someone approves. | Creating, updating, assigning, commenting, closing |
Not enabled | The tool is not available. LuumenAI cannot see or call it. | Deleting, bulk changes, anything your policy forbids |
Recommended Defaults
When you enable an integration, Recommended is pre-selected.
Read-only tools run automatically. Listing, searching, and checking status never need a sign-off.
Changes wait for a human. Anything that creates, updates, or deletes asks for approval first.
A tool the provider marks as destructive is set to Ask for approval and cannot be raised to Full access, whichever mode you pick. That floor holds even if you edit the permissions later.
Switch to Custom to tighten or loosen anything else. The defaults exist so governance works from the first day instead of being built tool by tool.
Organization and Workspace Scope
Organization Setting | Workspace May Set | Workspace May Not Set |
Full access | Ask for approval, Not enabled |
|
Ask for approval | Not enabled | Full access |
Not enabled |
| Ask for approval, Full access |
In the organization view, a tool whose permission differs between workspaces shows Mixed. Open the workspace to see its exact setting.
Setting and Changing Tool Permissions
Integration tool permissions are set and can be changed from an integration's Tool permissions.
Set all applies one level to every tool at once, which is the quickest way to start from all-reads-only and then open specific writes.
A few integrations publish their tools only after an account is connected. Those tools arrive with no permission, so LuumenAI cannot use them yet. Open the integration and give each new tool a permission.
What Members See
Members cannot see or change tool permissions. They can request an integration that is not enabled yet.


