# Channel permissions

Channel permissions narrow what Fennec may do when a message comes from an external audience. They supplement verified sender identity and runtime authorization; free-form guidance is not a security boundary.

![Channel permissions](https://www.foxora.ai/docs/images/v5.0.8/reference/settings-channels.webp)

*Studio interface in English. Sample data.*

## Apply least privilege

1. Open the channel's `Edit channel` view.
2. Expand `Advanced channel controls`.
3. Set `Plugin access` to `No plugins (safest)`, `Selected plugins`, or `All connected plugins`.
4. Enable `Read-only` when the channel should not perform write actions; choose an `Allowed plugins` list when applicable.
5. Add concise `Instructions` and `Data-use guidance`, then select `Update channel`.

## Expected result

Every plugin action is checked against the saved channel policy. Connection-management and remote-shell tools remain unavailable inside channels.
