Integration Permissions
Decide which tools Viktor runs on his own, which need your approval, who can use each connection, and what members may connect or change.
Three kinds of settings control what Viktor can do with a connected app: a permission level for each tool, who can use each connection, and workspace policies that decide what members may connect or change.
Set tool permissions
Every account has a Tools tab with one row per tool. Each tool has one of three levels:
- Off: Viktor can't use the tool.
- Run automatically: Viktor uses the tool without asking.
- Ask for confirmation: Viktor asks for approval each time before he uses it. See Approvals.
To change them:
- Open Integrations, select the app, then the account.
- On Tools, pick a level next to each tool. Use Search tools to find one; the search also matches the tool's internal name, like
pd_gmail_proxy_post. - To change every tool at once, open Actions and choose Reset all to defaults, Set all to run automatically, Set all to ask for confirmation or Set all to off.
When an account has more than plain tools, the list is split into groups:
- Created by Viktor: tools Viktor wrote on top of this app's API for work he does again and again. Each one asks for approval on every call until you set it to run automatically. Select Show code to read what it does before you do. Some carry a Read-only badge.
- Tools: the app's own actions.
- API requests: raw HTTP requests, one per method, against the whole API. They're broad, so asking for confirmation is the safer choice here.
If you follow a link from an approval message to change a tool's setting, the Tools tab opens with that tool already in the search box.
Change tool permissions from chat
You can also ask Viktor, for example "let the read-only Linear tools run automatically".
- Viktor reads the current levels and posts an approval request that describes the change.
- Someone approves or rejects it.
- The change only applies if the person who approves is allowed to change that integration's tools (see Limits).
This only works from a chat thread.
Who can use a connection
In Slack and Microsoft Teams workspaces, each account has an Access tab that answers Who should have access?:
- Everyone in the workspace: anyone on your team can use this connection.
- Private (Invite only): only the person who connected it and people they invite can use it. In Microsoft Teams-only workspaces this option is called Private, and only selected Teams members can use the connection.
When you choose the private option, a member picker opens so you can add people. The person who connected the account can't be removed: The connector always has access.
Only the person who connected the account can change this, and that includes admins who didn't connect it. Everyone else sees Only {name}, who connected this account, can change who can use it. While the account is locked, only a connector who is also an admin can change it.
What a private connection means in practice
- People who aren't on the list can't use the connection through Viktor, even when they ask him for it directly.
- A run with no person behind it, such as an automation nobody started from their own chat, can't use private connections. Viktor explains that the connection is set to private access and that retrying won't help, and suggests two fixes: the person who connected it switches it to team access on the Access tab (the message calls this "Team-only"; the option there is Everyone in the workspace), or sets the automation up from their own chat with Viktor. Automations a person creates run as that person and keep access to their private connections. See Scheduled tasks and Event triggers.
Admin policies
Admins set two policies in Settings > Permissions, under What teammates can do.
Who can connect new apps
Connect new integrations: When off, only admins can connect integrations.
When it's off, members:
- see Connecting new integrations is restricted to admins in your workspace. You can still use the integrations your team has already connected. on the Integrations page
- can't select connect on any card, or Add Custom
- can still use every integration that's already connected
Who can edit other people's integrations
Edit other people's integrations: When off, teammates can only edit integrations they set up themselves. This decides whether members can change the tools of accounts someone else connected.
Members who aren't admins see Only admins can change Viktor permissions on this page.
Limits
| Setting | Who can change it | While locked |
|---|---|---|
| Tool levels (web or chat) | The person who connected it, an admin, or any member if Edit other people's integrations is on | Admins only |
| Access tab | The person who connected it | Only if they are also an admin |
| Connect new integrations, Edit other people's integrations | Admins | — |
If you try to change tools you aren't allowed to, you see Only the creator or a team admin can change integration settings. To lock an account, see Manage integrations.
The Access tab and the Who can use it? choice only exist in Slack and Microsoft Teams workspaces. In other workspaces every connection is shared with the whole workspace.
Common problems
- A teammate can't use an app you connected: the account is private. Add them on the Access tab, or switch it to Everyone in the workspace. Only the person who connected it can do this.
- An automation fails with a message about private access: the run has no person behind it. Switch the connection to Everyone in the workspace, or have the person who connected it set up the automation from their own chat.
- The tool levels are greyed out: you aren't allowed to change this account, or it's locked. Ask the person who connected it or an admin.
- Connect buttons are disabled: an admin turned off Connect new integrations. Ask an admin to connect the app, or to turn the policy back on.