# Plugin permissions and security

A connected plugin introduces external data and actions. Grant the smallest provider scope and the smallest Foxora scope that complete the job.

![Plugin permissions and security](https://www.foxora.ai/docs/images/v5.0.8/reference/settings-plugins.webp)

*Studio interface in English. Sample data.*

## Limit access

1. Review the provider’s OAuth scopes or credential requirements before connecting.
2. Use a dedicated account when the task should not access a personal workspace.
3. Assign plugins and their tools only to the agents that need them.
4. For channels, set an explicit plugin allow-list and data-use rule.
5. Keep writes and sends behind task or workflow approval until tested.

## Expected result

A representative read succeeds, unrelated accounts or apps remain inaccessible, and a protected write pauses or is refused as expected. Never place OAuth tokens, API keys, or secrets in prompts, agent instructions, skill bodies, or screenshots.
