Skip to main content
Security & Privacy separates three decisions: who may contact the worker, who the worker may contact, and what connected tools it may use.

Inbound Access Policy

Inbound access does not grant outbound permission and does not override tool approvals.

Outbound Messaging Policy

Saved recipient rules

Recipient rules are explicit exceptions saved by channel and recipient address.
  • An allow rule pre-approves that recipient, which is useful for a scheduled report sent to a fixed email address.
  • A block rule prevents the worker from contacting that recipient.
  • A recipient cannot be both allowed and blocked. Remove the block before adding an allow rule.
  • Rules can be added in advance or saved when a team member approves a send.
Saved recipient rules work with the selected outbound policy; they do not change who may contact the worker.

Tool approval policy

Recommended is the default. “Unrestricted” applies to ordinary reads and writes; sends and destructive actions still require approval, and credential actions remain blocked.

Saved tool rules

Saved rules override the default tool policy for a specific connected tool:
  • Always allow lets the worker use that tool without asking where the action is eligible to be allowed.
  • Always block prevents the worker from using that tool.
  • A choice saved during an approval can appear here automatically.
  • Removing a saved rule returns the tool to the selected default policy.
Review allow rules carefully for tools that send messages, edit production systems, manage sensitive data, or delete records. Use the narrowest policy that still lets the worker complete its responsibilities.