Connecting an app, MCP server, or HTTP group does not automatically grant access to a digital human. Brain separates two decisions:
- Access: which digital humans are assigned to the connection.
- Tool policy: whether a tool is allowed, requires approval, or is blocked. This policy is global for your account.
Access per digital human
In the Connected digital humans section, each digital human has a toggle: turn it on to grant access to all of that connection's tools at once, turn it off to revoke it. You can search by name and page through the list if you have many digital humans.
Assignment is individual: granting access to one digital human does not grant it to the others.
Global policy for each tool
In Tool permissions, each tool (grouped into read-only and write) has one of these policies — set individually or in bulk per section:
| Policy | What it does |
|---|---|
| Allow always | The digital human uses it without asking you anything. |
| Require approval | Before running it, the digital human shows you a card to approve or decline the action. |
| Block | The digital human can't use it, even if it has access to the connection. |
By default, read-only tools are set to allow and write tools require approval — a sensible starting point you can adjust at any time.
Change permissions with the assistant
The Tool Studio Assistant can propose a policy change. Its review card states that the effect is global and requires explicit approval before anything is saved.
When a tool is missing mid-chat
If a digital human needs a tool it doesn't have while you're chatting, Brain surfaces it right there: it offers to connect it (if no one has connected it yet) or grant access (if it's already connected but not assigned to that digital human) — without leaving the conversation.