Connecting (binding) a connector requires the Administrator role on your
team. Administrators can also restrict any connector to specific members with
a member allow-list.
How permissions work — every connector
Two boundaries govern what happens through a connector:- The hard boundary is access control: who may use the connector at all. Only Administrators can bind or remove one, a per-binding member allow-list decides which teammates can use it, and within a session the agent only holds the credentials you explicitly selected. These checks are enforced server-side on every credential request — they are not something the agent can talk its way around.
- The soft boundary is what the agent may do with the access it has. Reads are free-form, but changes are packaged as plans that a human approves, and at the command level Auto-authorization decides which commands run on their own and which pause for your yes — with standing rules you control.
Cloud providers
AWS
Assume an IAM role via OIDC web-identity federation.
GCP
Impersonate a connector service account.
Cloudflare
Manage zones, DNS, and more with an API token.
Linode (Akamai)
Manage Linodes and LKE clusters.
Hetzner
Manage Hetzner Cloud servers and networks.
Tailscale
Access tailnet devices and policies.
Zeabur
Connect Zeabur projects and servers.
Source control
GitHub
Browse pull requests, workflows, and repositories.
GitLab
Connect gitlab.com or a self-hosted instance.
Observability
Grafana
Dashboards, alerts, and trace exploration.
Better Stack
Monitors, incidents, and telemetry.
Project management
Linear
Open, track, and close Linear issues.
Jira
Create, comment on, and transition Jira Cloud issues.
Compliance
Vanta
Read failing compliance tests and remediate.
Secureframe
Read failing compliance tests and remediate.
Messaging
Slack
Let the agent operate from Slack channels.
iMessage
Talk to the agent over iMessage.