Tools and skills
| Capability | Contents | Authority |
|---|---|---|
| Tools | MCP server actions that read from or write to connected systems | Limited by server, action, parameter, user authorization, and connection policy |
| Skills | Reusable instructions, supporting files, and static flags | Do not grant authority by themselves |
Approve actions
Catalog approval makes a tool available for setup. Runtime access combines the current server state, approved actions and parameters, user authorization, and connection policy.
- Approve all actions or a selected set.
- Limit which parameters an approved action can receive.
- Require human approval for a requested action when policy calls for it.
- Remove access on the next request when membership, catalog, consent, or approval changes.
Default-deny behavior
Missing policy never grants access. A model-only connection receives no MCP servers. A tool connection receives only the effective servers, actions, and parameters in its policy.
Connect user accounts
The workspace controls connector availability and action scope. Each user authorizes a provider account through OAuth; sign-in and consent remain with the provider.
Private tools and skills
Add a workspace-owned Streamable HTTP server or create a private skill. Releases retain source, version, digest, review state, and publication receipt.