Tool approvals
Require an administrator to approve the tools agents connect.
By default anyone who can configure an agent can connect a tool to it. Tool approvals put an administrator between that decision and the running agent: newly connected tools wait in a pending state until they are approved.
Once it is enabled, Settings → Tool approvals appears for Admins and Owners.
Turning it on#
The page appearing doesn't start the approval flow by itself. An Admin opens Settings → Tool approvals and turns on Require Tool Approval ("When enabled, new MCP tools added to agents require admin approval before they can be used").
What happens when it is on#
A tool connected to an agent is created as pending rather than approved. The agent cannot call it until an administrator acts on the request.
Requests appear under Tool Approval Requests, grouped by server. Use Filter by status to show Pending, Approved, Denied or All requests. Approve or deny a request on its own row, or act on everything pending from one server with Approve All or Deny All; Deny All asks you to confirm in the "Deny all tools from this server?" dialog.
Denying a request leaves the integration attached to the agent but unusable, so the person who added it can see the decision instead of finding the tool silently gone. To use a denied tool later, the builder requests approval again.
Scope of a decision#
Approvals are recorded against the integration, identified by its type and server, and can be narrowed to individual tools within a server. That means you can allow a server's read-only tools while withholding the ones that write.
Both managed servers from the catalog and custom MCP servers go through the same queue.