# Tool permissions

Permissions control whether a tool can run immediately or must ask you first.

Open **Settings → Permissions** to review the tools available to Syntheo.

## Permission choices

- **Ask:** pause and show you the request before the tool runs.
- **Allow:** let the tool run without asking each time.

During a task, an approval request may also offer:

- **Allow Once:** approve only this request;
- **This Turn:** approve repeated use during the current run;
- **Deny:** reject the request.

## Recommended starting settings

Keep these on **Ask** until you understand their scope:

- file writes;
- Terminal or command tools;
- Git actions;
- Browser and network access;
- deployment or publishing actions;
- newly installed connected tools.

Read and search tools are lower risk, but you should still understand which workspace or service they can access before allowing them globally.

## Review an approval

Before allowing a request:

1. Check the tool name.
2. Read every argument.
3. Confirm the command, path, URL, account, and workspace.
4. Decide whether the action is necessary for the current goal.
5. Choose the shortest useful approval duration.

Use **Allow Once** when in doubt. Use **This Turn** only after you have seen a safe request and expect the same tool to repeat within the current task.

## Deny and redirect

Denying a request does not end the task. Tell Syntheo what it may do instead:

```text
Do not run the deployment. Use the local preview check and report the result.
```

```text
Do not write outside this workspace. Explain which outside file you need and why.
```

## Review permissions over time

- Return a tool to Ask if its purpose changes.
- Keep newly added tools on Ask while you evaluate them.
- Remove tools and connections you no longer use.
- Revoke provider or service credentials when access is no longer needed.
- Never approve a request only because the task appears stuck.

## Next

Learn how to extend Syntheo in **[Skills and connected tools](skills-and-tools.md)**.

[← Models and providers](models.md) · [Settings and safety](README.md) · [Documentation use notice](../NOTICE.md)
