Skip to main content

Integration Tool Permissions

The three permission levels on every integration tool, and the recommended defaults.

Written by Braden Ericson

Permission is set on each individual tool an integration offers, not on the integration as a whole. This lets you allow ServiceNow reads to run freely while ServiceNow writes wait for approval, and lets you make a destructive call unavailable entirely.

The Three Permission Levels

Tool permissions are set when enabling an integration and can be changed.

Level

What LuumenAI Can Do

Typical Use

Full access

Run the tool without asking. The call still appears live in the conversation and lands in the audit log.

Listing, searching, reading a record, or checking status

Ask for approval

Propose the call and wait. The conversation shows the exact call, the evidence, and a risk level; the tool runs only when someone approves.

Creating, updating, assigning, commenting, closing

Not enabled

The tool is not available. LuumenAI cannot see or call it.

Deleting, bulk changes, anything your policy forbids

Recommended Defaults

When you enable an integration, Recommended is pre-selected.

  • Read-only tools run automatically. Listing, searching, and checking status never need a sign-off.

  • Changes wait for a human. Anything that creates, updates, or deletes asks for approval first.

A tool the provider marks as destructive is set to Ask for approval and cannot be raised to Full access, whichever mode you pick. That floor holds even if you edit the permissions later.

Switch to Custom to tighten or loosen anything else. The defaults exist so governance works from the first day instead of being built tool by tool.
​


Organization and Workspace Scope

Organization Setting

Workspace May Set

Workspace May Not Set

Full access

Ask for approval, Not enabled

Ask for approval

Not enabled

Full access

Not enabled

Ask for approval, Full access

In the organization view, a tool whose permission differs between workspaces shows Mixed. Open the workspace to see its exact setting.

Setting and Changing Tool Permissions

Integration tool permissions are set and can be changed from an integration's Tool permissions.
​
​Set all applies one level to every tool at once, which is the quickest way to start from all-reads-only and then open specific writes.
​

A few integrations publish their tools only after an account is connected. Those tools arrive with no permission, so LuumenAI cannot use them yet. Open the integration and give each new tool a permission.

What Members See

Members cannot see or change tool permissions. They can request an integration that is not enabled yet.

Related articles

Did this answer your question?