Tool permissions
When the AI wants to use a tool — run a command, call a connector, touch a file — Harriet Desktop pauses and asks you first. This page explains the permission prompt, the three answers you can give, and how your organization's settings shape what the AI can ask for at all.
The permission prompt
Mid-task, the session stops on a dialog titled Permission Required. It names the exact permission being requested under a Permission label, shows the scope it applies to, and offers an expandable details section with the full request. Nothing runs until you answer.
You have three options:
- Once — allow this single action, then ask again next time. The safe default when you're unsure.
- Allow for session — allow this permission for the rest of the current session. Good for a repetitive task, like a finance close where the AI reads dozens of files from the same folder.
- Deny — refuse the action. The AI is told no and continues without it.
If the AI keeps retrying the same denied action, the prompt calls it out with a loop warning: "Reject to stop the loop, or allow if you want the agent to keep trying."
Why the prompts exist
The prompt is the line between "the AI suggested something" and "the AI did something". A salesperson can let the AI draft an outreach email freely but still gets asked before a connector sends anything; an IT admin can let it read logs all afternoon and still approve each configuration change. You stay in control of actions with consequences, without approving every keystroke.
The same boundary applies to files: the app only works inside folders you have authorized as workspaces, so sharing your project folder never quietly exposes the rest of your machine.
What gets audited
Approving a prompt is a local decision; the record is central. Tool calls that go through Harriet's connectors are logged in the audit log: who called what, from which device, with which skill, and whether it worked. That trail is what lets your organization roll out AI to finance and operations teams that answer to auditors.
What shapes the list of tools
You only see prompts for tools you can actually reach. Admins control which connector tools are exposed per profile and per connector — see tool permissions — so a tool your organization has switched off never appears in a prompt at all. If a tool you expect is missing rather than denied, that page and your admin are the place to start, not the prompt.