Skip to main content
An integration exposes a reviewed set of operations. Connecting a provider does not expose its entire API or authorize every action its website supports.

Two permission systems apply

Every action must pass both:
  • Fractal permissions: workspace/resource access, required membership, operation policy, and domain restrictions.
  • Provider permissions: the connected account’s scopes, roles, object access, and any selected capability limits.
Neither system overrides the other. Giving an agent write permission cannot make a provider’s read-only account writable. Agent Details offers Read only, Read and write, and Read/write/delete. Resource access and allowed effects must both authorize the operation.

Supported operations at a glance

This is a capability summary; the tools available to your connection can be narrower. Box and Dropbox coverage does not imply general file upload/download, bulk deletion, or sharing administration. Snowflake’s configured role still determines which SQL statements can succeed.

Google capabilities are selected separately

The tools reflect both your selected capability ceiling and the permissions Google actually granted. A broad Google scope does not silently re-enable a capability you left unselected. Existing read-only connections do not automatically gain writes. Reconnect with the intended capabilities when needed.

Read-only has a defined scope

The platform policy constrains resource APIs, integration tools, and Git access. It does not restrict every local sandbox command or independently supplied credential. Some native output actions have explicit exceptions: an agent can reply in its own conversation and create a new Page while read-only. Updating an existing Page or posting to a channel still requires the corresponding write authority. Comments follow Page access, with applicable agent operation permissions. See Comments and passage changes.

Writes can affect other people

A supported write may send email, notify calendar attendees, trigger a ticket workflow, or update shared content. State the intended account, target, and action in the request. If a write’s result is uncertain, check the existing operation or result before asking the agent to repeat it. A timeout does not prove the provider made no change.

Google Drive file-editing limits

Drive writes support text, Markdown, CSV, and JSON files up to 1 MiB. Editing replaces the complete file and requires both Read files and Write files. Review the intended replacement rather than assuming it is a small patch. Rich Google Docs, Sheets, and Slides editing is not included in this capability. Folder creation, copying, renaming, trashing, and restoring are separate supported operations with their own permission requirements. For Snowflake service-user setup and verification, see Connect Snowflake.