Approvals and permissions
Choose when Fluso asks before connector and MCP tool actions, review approval cards, and manage saved tool rules.
Approvals let you decide how much Fluso can do without stopping for confirmation. You can keep every connector and MCP tool action behind a prompt, or let Fluso run them automatically.
Your choice belongs to a chat. Existing chats keep their current mode. A choice made before a new chat starts is pending until you send the first message and the chat is created.
Organization rules and your saved Deny rules always apply. An automatic mode cannot override them.
Choose an approval mode
| Mode | Connector and MCP tools |
|---|---|
| Ask for everything | Ask before a tool runs |
| Don't ask permission | Approve tools automatically |
Use Ask for everything when you want to review each action before a tool can read or change data. Don't ask permission is best for work you trust Fluso to finish without waiting for you.
Set the mode from the composer
Open the permission menu
Start a new chat and click the shield control beside the model mode in the composer.
Choose a mode
Pick Ask for everything or Don't ask permission. The menu explains which requests will still pause.
Send the first message
Before a thread exists, the composer labels the choice as Pending. Sending your first message creates the chat and confirms its mode.
You can change the mode between messages. The updated choice applies to later actions in that chat. It does not change other existing chats.
Connector tool approval cards
Connector and MCP tools can read or change data in another service. When a tool needs approval, the card shows the connector or server, tool name, a short argument summary, and an expandable view of the exact arguments.
You can choose:
- Allow once to run this tool only with the arguments shown on the card.
- Always allow to save an allow rule for this tool.
- Deny to reject this request without creating a permanent tool deny.
If the required app is not connected, the card asks you to Connect first. Complete sign-in and Fluso resumes the waiting action. If the request changes while you are deciding, it fails closed instead of applying your decision to different arguments.
If the card expires or the run is canceled before you decide, ask Fluso to try the action again. An organization-managed deny is locked and cannot be approved from chat.
Use Allow once for a sensitive write or an unusual set of arguments. Use Always allow for a tool you expect this chat to call repeatedly.
Manage approvals in Settings
Open your account menu, choose Settings, then open Approvals & permissions. This panel controls the mode for your next new chat.
Set the default for the next chat
The Auto-approval section has the same modes as the composer. A Settings change is staged for your next new chat. It does not rewrite the mode of chats that already exist.
Which rule wins
Fluso applies the most restrictive relevant rule. In practical terms:
- An organization Deny always blocks the tool.
- Your Deny can block something the organization allows.
- An organization Allow can make an action available, unless you denied it.
- Your Allow can approve an action when the organization has not blocked it.
- With no saved rule, the current chat mode decides whether Fluso asks or continues automatically.
This is why switching to Don't ask permission does not open something that your organization or you explicitly blocked.
Manage MCP tool rules
Open Plugins, select an MCP server, and open its tool permissions. Each tool can be set to Allow, Ask, or Deny.
You can also enable automatic approval for tools classified as read-only, such as list, search, fetch, and GET operations. An explicit Ask or Deny on a tool takes precedence over that read-only setting.
See MCP servers for connection setup and credential handling.
Troubleshooting
I changed the mode in Settings, but this chat still asks
Settings changes apply to the next new chat. Existing chats keep their current mode. Change the shield control in this chat, or start a new one.
The composer says Pending
The chat has not been created yet. Send the first message to commit that mode to the new chat.
An approval card expired
Ask Fluso to retry the action. Approval cards are bound to one pending request and cannot approve a later or changed request.
I chose Always allow, but a different connector tool still asks
Tool rules apply to the specific tool, not every tool on the connector or MCP server. Review that server's tool permissions under Plugins.
A tool is blocked and no approval card appears
Check that server's tool permissions under Plugins for a saved Deny. If the rule is locked or marked as managed by your organization, only an organization administrator can change it.
Next
See Chat for thread and composer behavior, and Apps and MCP servers for app access and third-party tools.