> ## Documentation Index
> Fetch the complete documentation index at: https://plasma-ai.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Capabilities and permissions

An integration exposes a reviewed set of operations. Connecting a provider does not expose its entire API or authorize every action its website supports.

## Two permission systems apply

Every action must pass both:

* **Fractal permissions:** workspace/resource access, required membership, operation policy, and domain restrictions.
* **Provider permissions:** the connected account's scopes, roles, object access, and any selected capability limits.

Neither system overrides the other. Giving an agent write permission cannot make a provider's read-only account writable.

Agent Details offers **Read only**, **Read and write**, and **Read/write/delete**. Resource access and allowed effects must both authorize the operation.

## Supported operations at a glance

This is a capability summary; the tools available to your connection can be narrower.

| Integration | Capability level | Examples and boundaries |
| - | - | - |
| Figma | Read-only | Read files, nodes, rendered images, components, styles, and comments. No design edits or comment posting. |
| Granola | Read-only | Read notes, transcripts, and folders. No note editing. |
| Linear | Reads and selected writes | Find/read issues; create/update issues; read/create comments. No general destructive operations or arbitrary GraphQL. |
| Notion | Reads and selected writes/deletes | Read pages and blocks; append/delete blocks; create comments and databases. |
| Box | Reads and selected writes | Search, metadata, folder listings/creation, and comments. |
| Dropbox | Reads and selected writes | Search, metadata, folder listings, and folder creation. |
| HubSpot | Reads and selected writes | Read/create supported contacts, companies, and deals; update contacts. |
| Jira | Reads and selected writes | Read/create/update issues, add comments, and apply supported transitions. |
| Confluence | Reads and selected writes | Read/create/update pages and read/add footer comments. No sharing administration. |
| Zendesk | Reads and selected writes | Read/create/update tickets, including public replies or internal notes. |
| Intercom | Reads and selected writes | Read/create contacts; read conversations, reply, or add admin notes. |
| PostHog | Reads and selected writes | Read dashboards/insights, run bounded analytics queries, and create annotations. |
| Sentry | Reads and selected writes | Read projects/issues/events and update issue status. |
| Snowflake | Read browsing; permission-gated SQL | Browse databases/schemas/tables. Arbitrary SQL requires read, write, and delete platform permissions, even for a SELECT. |

Box and Dropbox coverage does not imply general file upload/download, bulk deletion, or sharing administration. Snowflake's configured role still determines which SQL statements can succeed.

## Google capabilities are selected separately

| Service | Available capability choices | Important distinction |
| - | - | - |
| Drive | Read files; write files | Supported writes cover bounded text-file and folder operations, not general rich-document editing. |
| Gmail | Read email; organize email; create drafts; send email | Creating a draft and sending an email are separate actions. |
| Calendar | Read calendars; write events | Reading availability does not create an event. Event updates/deletes require current versions and can notify attendees. |

The tools reflect both your selected capability ceiling and the permissions Google actually granted. A broad Google scope does not silently re-enable a capability you left unselected.

Existing read-only connections do not automatically gain writes. Reconnect with the intended capabilities when needed.

## Read-only has a defined scope

The platform policy constrains resource APIs, integration tools, and Git access. It does not restrict every local sandbox command or independently supplied credential.

Some native output actions have explicit exceptions: an agent can reply in its own conversation and create a new Page while read-only. Updating an existing Page or posting to a channel still requires the corresponding write authority.

Comments follow Page access, with applicable agent operation permissions. See [Comments and passage changes](/fractal-product/working-with-agents/comments).

## Writes can affect other people

A supported write may send email, notify calendar attendees, trigger a ticket workflow, or update shared content. State the intended account, target, and action in the request.

If a write's result is uncertain, check the existing operation or result before asking the agent to repeat it. A timeout does not prove the provider made no change.

## Google Drive file-editing limits

Drive writes support text, Markdown, CSV, and JSON files up to **1 MiB**. Editing replaces the complete file and requires both **Read files** and **Write files**. Review the intended replacement rather than assuming it is a small patch.

Rich Google Docs, Sheets, and Slides editing is not included in this capability. Folder creation, copying, renaming, trashing, and restoring are separate supported operations with their own permission requirements.

For Snowflake service-user setup and verification, see [Connect Snowflake](/fractal-product/integrations/snowflake).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.