# Control what ZeroTwo can do in a connected app

> Set each connector tool to Always allow, Needs approval or Blocked, change a group at once, and understand the approval prompt.

Source: https://help.zerotwo.ai/en/articles/20001495-control-what-zerotwo-can-do-in-a-connected-app
Section: ZeroTwo > Connectors and plugins
Last updated: 2026-10-05

Every connected app comes with a list of tools, and each tool has a permission. Use these permissions to stop ZeroTwo from sending, deleting or changing things in an app without your say-so. You set them on the app's page in Customize.

## Open an app's tool permissions

1. Go to **Customize > Connectors**.
2. Select a connected app under **Installed**.
3. Find the **Tool permissions** section. It reads "Choose when the agent is allowed to use these tools."

Tools are split into **Read-only tools** and **Write/delete tools**, and each group shows how many tools it holds. Where a tool has a description, hover the info icon beside it to read it. ZeroTwo sorts a tool using the server's own read-only flag when there is one, and the words in the tool's name otherwise, so check both groups to make sure the sorting makes sense for the app.

If the list is empty, the page says "No tools available for this connector." Open **More options** and choose **Refresh tools** to load the list again.

## The three settings

| Setting | What it does |
| --- | --- |
| Always allow | ZeroTwo can use the tool without asking. Tools start here. |
| Needs approval | When ZeroTwo runs your request as an agent task, it pauses and asks before using the tool. That is always the case in Work and Code. In Chat it applies to messages that ZeroTwo handles as agent tasks, such as requests that need a connected app. |
| Blocked | The tool is hidden from ZeroTwo everywhere, so it cannot use it. This also covers calls made by interactive widgets from the same server. |

Each tool's row has a three-button control, with buttons labelled **Always allow**, **Needs approval** and **Blocked**. Select one to change the tool.

## Change a whole group at once

Each group header has a menu showing the group's current setting. Choose **Always allow**, **Needs approval** or **Blocked** to apply it to every tool in the group. When the tools in a group do not all match, the menu reads **Custom**.

## What the approval prompt looks like

When an agent run reaches a Needs approval tool, ZeroTwo pauses and shows an approval card with a short question about the action. What the card offers depends on the app you use.

### Web and desktop apps

- **Yes** runs the tool this one time.
- **Yes, and don't ask again this task** stops further prompts for that account and tool until the current task ends.
- The text box "No, and tell ZeroTwo what to do differently" declines the call. Type a note in it first if you want ZeroTwo to know why. If you have set a name under Settings > Personalization > Companion's name, the text uses that name instead of ZeroTwo.

Select an option and choose **Submit**. **Skip** declines the call straight away. When you decline, ZeroTwo is told not to retry and to carry on without the tool.

These apps do not offer a choice that changes the permission for good. To stop the prompts for a tool, set it to **Always allow** on the app's page.

### iOS and Android apps

The mobile apps show the choices exactly as ZeroTwo sends them: **Allow once** runs the tool this one time, **Allow for this run** stops further prompts for that account and tool during the current task, **Always allow for this account** changes that connected account's permission for the tool to Always allow, and **Deny** skips the call.

### Runs that cannot ask

If a run has nobody to ask, such as a scheduled or background run, tools set to Needs approval are not run.

## Good habits

- Set write and delete tools to **Needs approval** for apps that hold important data, such as your email or files.
- Set tools you never want used to **Blocked** rather than leaving them on.
- To stop an app entirely without losing the connection, switch it off in **Settings > Plugins > Connectors**.

## On iOS and Android

The ZeroTwo apps for iOS and Android show the same Tool permissions section with the same three settings.

## Related

- [Connect your apps to ZeroTwo with connectors](https://help.zerotwo.ai/en/articles/11487775-connect-your-apps-to-zerotwo-with-connectors)
- [Connect, reconnect and disconnect app accounts](https://help.zerotwo.ai/en/articles/20001494-connect-reconnect-and-disconnect-app-accounts)
