# Tool permissions and approvals

Tool access is layered: agent assignment, task mode, operating-system permission, connected-account scope, and hard Runtime policy all apply.

![Tool permissions and approvals](https://www.foxora.ai/docs/images/v5.0.8/reference/tools.webp)

*Studio interface in English. Sample data.*

## Choose safe authority

1. Assign the tool only to agents that need it.
2. Use `Ask permissions` for unfamiliar work and review each proposed action.
3. Use `Accept edits` when file edits are expected but commands still need review.
4. Use `Auto mode` only for trusted, bounded work you can verify.
5. Reserve `Full Access` for controlled environments; it does not override protected-action policy.

## Expected result

Read-only work proceeds with minimal interruption, while write, execute, external, or destructive actions pause as configured. If a call is blocked, change the specific missing permission instead of broadly expanding every capability.
