---
slug: agent-tool-access
title: Which tools an Agent may use
category: capability
status: published
tags: [agent access, agent tools, agent connector, agent connector access, agent tool access, connector access, connector grant, allowed tools, grant, permission, allowlist, whole company, only what i pick, agent 权限, 连接器授权, 工具授权, 只用我勾选的, 授权]
aliases: []
lastEditAt: 2026-09-20
---
**Where do I set this?**

Open **Setup → Agents** and click the Agent's row. Its **Access** block decides which connected tools that Agent may use. The block header reads **Whole company** or **3 allowed**, and one **Save** at the bottom of the panel stores the whole row.

**What are the two modes?**

**Whole company** lets the Agent use every connector your company has connected, including ones you connect later. **Only what I pick** narrows it to the tools you check. An Agent you just created starts with nothing allowed, so grant its tools here before you expect it to reach Gmail, GitHub, or Slack. Tycoon Agent herself is the default for every channel and connector, so there is nothing to narrow on her row.

An Agent imported with its own declared tool list has no **Whole company** option — it can use only what you allow. With nothing checked, the panel says the Agent has no tools.

**A tool isn't listed.**

Only connected services appear here. Connect it under **Setup → Connectors** first, then come back and allow it.

**Why can't my Agent use a tool I connected?**

Because connecting a tool does not grant it. If the Agent is narrowed and that tool isn't checked, the call is refused before it reaches the third-party service, and the Agent asks you for the grant instead of working around it. Anyone in your workspace can grant it here.

**What does it cost?**

Changing access costs nothing. A tool the Agent actually calls is billed as part of that task's work, like any other connector usage.

See also [where the Connectors tab is](/help/integrations-tab) and [what the team roster is](/help/what-is-the-team-roster).
