A client reaches nothing until you add an application to it and pick a level.

Levels are a ladder, and each rung includes the ones below it. Mail runs Off,
Read, Draft, Manage, Full. Calendar runs Off, Read, Full. Anything else is on or
off.

## Changing them

Open the client, then **Applications**. Changes apply to every connection on that
client at once, from its next call. Nothing needs reconnecting.

<figure>
  <a href="/docs/tools/permissions.png"><picture>
    <source srcset="/docs/tools/permissions-dark.png" media="(prefers-color-scheme: dark)">
    <img src="/docs/tools/permissions.png" alt="The applications on one client. Exa with web search on. Firecrawl with page reading on. A Google account with Gmail set to Manage and Calendar set to Read, each level a row of buttons from Off through Full.">
  </picture></a>
  <figcaption><strong>A level per application, not one setting for everything.</strong> This client can manage mail and read the calendar. Moving Gmail to Read would take away its ability to file and label, and nothing else would change.</figcaption>
</figure>

There is no Save. Each change is saved as you make it, and the next call an
assistant makes uses the new level.

## When an assistant asks for one

An assistant that needs a permission it does not have will say so, name the
application and the level, and give you this page. It cannot grant itself
anything, and a link it hands you never carries a change in it: opening a link
only ever shows you the page. You make the change.

## More than one account

If you have connected several accounts of the same kind, each is its own
application with its own permissions, and calls say which account answered. An
assistant that could mean more than one will ask which, rather than guess.