Introduction
Every connector you enable in Sana comes with a set of tools — the individual actions an agent can perform in that app, such as searching messages in Slack, reading a file in Google Drive, or sending an email in Gmail. Tool controls let a workspace owner decide which of these tools users and agents in the workspace are allowed to use. Turning off a tool withholds it from every user and agent in the workspace: the agent no longer has access to it and cannot use it, even if a user asks for it directly.
Who can do what
Who | Where | What |
Workspace owner | Workspace settings > Connectors | Workspace owners can:
|
Workspace member | User settings > Connectors | Workspace members can:
|
How workspace owners can configure tools:
Workspace owners can configure which tools are available for a connector both before and after the connector has been added, as described below.
Configuring tools before enabling a connector
Go to Workspace settings > Connectors > Add connector.
Select the connector you want to add.
After choosing who will have access to the connector, you'll reach the Tools step.
Configure the tools (optional):
To set a tool group control: toggle the switch on the top-level row of either collapsible section — "Read-only tools" or "Write tools". This sets the default value for that group and all its tools; any new tools added to Sana later automatically inherit the group's default.
To override a specific tool: toggle that tool's individual switch. To revert it to the group default, click the cross icon.
Click Enable at the bottom.
Configuring tools after enabling a connector
Go to Workspace settings > Connectors.
In the list of enabled connectors, click the one you want to modify.
Scroll down to the Tools section:
To set a tool group control: toggle the switch on the top-level row of either collapsible section — "Read-only tools" or "Write tools". This sets the default value for that group and all its tools; any new tools added to Sana later automatically inherit the group's default.
To override a specific tool: toggle that tool's individual switch. To revert it to the group default, click the cross icon.
Click Save at the bottom.
FAQ
Q: What happens to my tool configurations when new tools are launched?
A: When a connector adds a new tool, it inherits the default of its group. If you rely on Write tools being off, leave the group default off rather than disabling tools one by one.
Q: Which tools are enabled by default?
A: All tools are available by default.
Q: Which connectors support tool controls?
A: All real-time connectors powered by Pipedream, as well as custom MCP connectors. The one exception is the Workday connector, which does not currently support tool controls.
Q: What happens if a user or agent tries to use a disabled tool?
A: Sana enforces this at the platform level: the tool is disabled for both the user and the agent, so it cannot be called.
Q: What are tool groups?
A: Tools fall into one of two groups: read-only or write. Read-only tools let you read data in another system; write tools let you create, update, or delete data in that system.
Q: Can workspace members configure which tools are available to them, i.e. override what the admin has configured?
A: No.
Q: Can I give some users access to certain tools but not others?
A: No — access controls currently apply at the workspace level, so either everyone in the workspace has access or no one does. We're looking into more granular controls over time.
Q: Can I control which tools require human-in-the-loop approval?
A: Not currently, but it's on our roadmap. By default, all write tools require approval, while read tools do not.
Known limitations
The Workday connector does not support tool configurations.
Tool controls apply at the workspace level; they don't offer user or user-group granularity.

