Two permission systems apply
Every action must pass both:- Fractal permissions: workspace/resource access, required membership, operation policy, and domain restrictions.
- Provider permissions: the connected account’s scopes, roles, object access, and any selected capability limits.
Supported operations at a glance
This is a capability summary; the tools available to your connection can be narrower.
Box and Dropbox coverage does not imply general file upload/download, bulk deletion, or sharing administration. Snowflake’s configured role still determines which SQL statements can succeed.
Google capabilities are selected separately
The tools reflect both your selected capability ceiling and the permissions Google actually granted. A broad Google scope does not silently re-enable a capability you left unselected.
Existing read-only connections do not automatically gain writes. Reconnect with the intended capabilities when needed.