Tool permissions
Permissions control whether a tool can run immediately or must ask you first.
Open Settings → Permissions to review the tools available to Syntheo.
Permission choices#
- Ask: pause and show you the request before the tool runs.
- Allow: let the tool run without asking each time.
During a task, an approval request may also offer:
- Allow Once: approve only this request;
- This Turn: approve repeated use during the current run;
- Deny: reject the request.
Recommended starting settings#
Keep these on Ask until you understand their scope:
- file writes;
- Terminal or command tools;
- Git actions;
- Browser and network access;
- deployment or publishing actions;
- newly installed connected tools.
Read and search tools are lower risk, but you should still understand which workspace or service they can access before allowing them globally.
Review an approval#
Before allowing a request:
- Check the tool name.
- Read every argument.
- Confirm the command, path, URL, account, and workspace.
- Decide whether the action is necessary for the current goal.
- Choose the shortest useful approval duration.
Use Allow Once when in doubt. Use This Turn only after you have seen a safe request and expect the same tool to repeat within the current task.
Deny and redirect#
Denying a request does not end the task. Tell Syntheo what it may do instead:
Do not run the deployment. Use the local preview check and report the result.Do not write outside this workspace. Explain which outside file you need and why.Review permissions over time#
- Return a tool to Ask if its purpose changes.
- Keep newly added tools on Ask while you evaluate them.
- Remove tools and connections you no longer use.
- Revoke provider or service credentials when access is no longer needed.
- Never approve a request only because the task appears stuck.
Next#
Learn how to extend Syntheo in Skills and connected tools.
← Models and providers · Settings and safety · Documentation use notice