> ## Documentation Index
> Fetch the complete documentation index at: https://docs.conduit.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Tool Permissions

> Which Conduit MCP tools read data, which change it, and which take consequential actions that need approval every time.

Every Conduit MCP tool falls into one of three classes. Use them to decide which tools a client may run without asking.

| Class | What it does | Recommended approval |
| - | - | - |
| **Read** | Retrieves information. No data, account state, or permissions change. | Safe to always allow. |
| **Write** | Creates or changes data in your Conduit workspace. Can be undone or edited afterwards. | Ask on first use; always allow is acceptable. |
| **Sensitive write** | Sends a message or email to someone outside your team, changes physical access to a property, accepts or declines a guest's reservation change, books or changes an appointment with a contact, runs or schedules an agent or custom code that can act on its own, or permanently deletes data. | Ask every time. Never always allow. |

The `readOnlyHint` annotation on each tool matches its class: `true` for Read, `false` for both write classes. A tool that both reads and writes is classified as a write.

## Connection permissions

The OAuth consent screen lets you choose **Read only** even when the client asks for write access. A read-only connection can call Read tools only; every write tool returns an error result (`isError: true`) with code `forbidden`. API tokens follow the same rule: a read-only `capi_` token rejects every write tool.

## Search mode

OAuth and API-token connections list two tools, `search_tools` and `call_tool`, and reach every tool below through them.

| Tool | Class |
| - | - |
| `search_tools` | Read |
| `call_tool` | Takes the class of the tool it calls. A client that approves per tool name should treat `call_tool` as a sensitive write. |

## Sensitive write

These tools act on people or property outside Conduit, or cannot be undone. `send_conversation_message` and `send_ticket_message` accept an `idempotency_key`, but most channels do not yet use it to block a duplicate. Do not retry a send that may have succeeded.

| Area | Tools |
| - | - |
| Agents | `delete_agent`, `delete_agent_guardrail`, `run_agent` |
| Contacts | `delete_custom_attribute` |
| Conversation tags | `delete_conversation_tag` |
| Conversations | `send_conversation_message`, `send_message`, `send_system_email` |
| Custom tools | `delete_custom_tool`, `run_custom_tool` |
| Devices | `assign_backup_access_code`, `create_access_code`, `delete_access_code`, `set_lock_state`, `update_access_code` |
| Listings | `delete_listing_group` |
| Operator skills | `delete_operator_skill` |
| Portals | `delete_portal_template`, `delete_verification_rule` |
| Reservations and appointments | `respond_to_reservation_alteration` |
| Schedules | `schedule_cron`, `schedule_wake` |
| Skills | `delete_skill` |
| Tasks | `task_delete` |
| Tickets | `delete_ticket_note`, `send_ticket_message` |
| Voice agents | `delete_voice_agent` |

## Write

| Area | Tools |
| - | - |
| Agents | `create_agent`, `create_agent_guardrail`, `patch_agent`, `patch_agent_guardrail`, `set_agent_skill_access`, `set_agent_tool_access`, `simulate_conversation` |
| Call groups | `create_call_group`, `patch_call_group` |
| Contacts | `contact_update_custom_field`, `create_contact`, `create_custom_attribute`, `create_custom_attribute_section`, `patch_contact`, `patch_contact_custom_attributes`, `patch_custom_attribute`, `patch_custom_attribute_section`, `pause_contact_ai`, `resume_contact_ai` |
| Conversation tags | `create_conversation_tag`, `patch_conversation_tag` |
| Conversations | `assign_conversation`, `leave_note` |
| Custom tools | `create_custom_tool`, `update_custom_tool` |
| Devices | `assign_device_property`, `set_noise_threshold`, `set_thermostat` |
| Escalations | `assign_escalation`, `resolve_escalation` |
| Google Drive | `import_drive_file`, `set_drive_split_mapping` |
| Insights | `generate_pdf`, `query_insights` |
| Knowledge sources | `cancel_knowledge_source_sync`, `set_knowledge_source_sync` |
| Listings | `add_listings_to_listing_group`, `create_listing_group`, `set_listing_active` |
| Operator skills | `create_operator_skill`, `patch_operator_skill` |
| Portals | `archive_portal_guide`, `archive_portal_offer`, `archive_portal_template`, `create_portal_guide`, `create_portal_offer`, `create_portal_template`, `create_verification_rule`, `duplicate_portal_guide`, `duplicate_portal_template`, `get_portal`, `patch_portal_brand_kit`, `patch_portal_guide`, `patch_portal_offer`, `patch_portal_template`, `patch_verification_rule`, `reorder_portal_guides`, `reorder_verification_rules`, `restore_portal_guide`, `restore_portal_offer`, `restore_portal_template`, `update_portal` |
| Schedules | `schedule_cancel` |
| Skills | `create_skill`, `patch_skill` |
| Tasks | `task_add_comment`, `task_add_requirements`, `task_attach_image`, `task_attach_message_media`, `task_create`, `task_finalize_image_upload`, `task_prepare_image_upload`, `task_set_assignee`, `task_set_custom_fields`, `task_set_due_at`, `task_set_requirement`, `task_update`, `task_update_status` |
| Tickets | `close_ticket`, `create_ticket_note`, `reopen_ticket`, `resolve_ticket`, `update_ticket_note` |
| Voice agents | `create_voice_agent`, `patch_voice_agent` |
| Workflows | `apply_workflow_edits`, `clone_workflow`, `create_workflow`, `create_workflow_folder`, `move_workflow_to_folder`, `update_workflow` |

## Read

| Area | Tools |
| - | - |
| Agent runs | `get_agent_run`, `get_agent_runs_by_session_id`, `get_agent_trace`, `list_agent_runs`, `list_agent_sessions` |
| Agent triggers | `get_trigger_event` |
| Agents | `get_agent`, `list_agent_connections`, `list_agent_guardrails`, `list_agent_tools`, `list_agents` |
| Analytics | `describe_bigquery_tables`, `execute_bigquery_query` |
| Billing | `get_billing_usage` |
| Calls | `get_call`, `list_airbnb_transactions`, `list_calls` |
| Contacts | `contact_list_custom_fields`, `find_contact_by_phone`, `get_contact`, `get_contact_allocation`, `get_contact_custom_attributes`, `get_contact_detail`, `list_contact_appointments`, `list_contact_calls`, `list_contact_helpdesk_tickets`, `list_contact_reservations`, `list_contact_tickets`, `list_contacts`, `list_custom_attribute_sections`, `list_custom_attributes`, `search_contacts` |
| Conversation tags | `get_conversation_tag`, `list_conversation_tags` |
| Conversations | `get_channels_for_contact`, `get_chat_history_by_channel`, `get_chat_history_by_contact`, `get_conversation`, `get_message_templates`, `list_conversation_assignment_events`, `list_conversation_messages`, `list_conversations`, `list_message_senders`, `search_conversations` |
| Custom tools | `get_custom_tool`, `list_custom_tool_runtimes`, `list_custom_tools` |
| Devices | `get_access_code`, `get_device_history`, `get_device_telemetry`, `list_access_codes`, `list_devices` |
| Escalations | `list_escalations` |
| Google Drive | `get_drive_file`, `list_drive_connections`, `list_drive_files`, `propose_drive_split_mapping`, `search_drive_files` |
| Helpdesk | `get_helpdesk_ticket`, `list_helpdesk_tickets` |
| Insights | `get_automation_rate`, `get_resolution_rate` |
| Knowledge sources | `list_knowledge_sources` |
| Listings | `check_listing_availability`, `get_listing`, `list_listing_cities`, `list_listing_group_listings`, `list_listing_groups`, `list_listings`, `search_listing_availability` |
| Local recommendations | `get_directions`, `google_places_recommendations` |
| Operator skills | `list_operator_skills` |
| Portals | `get_checkin_status`, `get_customer_portals`, `get_portal_brand_kit`, `get_portal_guide`, `get_portal_offer`, `get_portal_session`, `get_portal_template`, `get_verification_rule`, `list_portal_guides`, `list_portal_offer_catalog`, `list_portal_offers`, `list_portal_sessions`, `list_portal_template_catalog`, `list_verification_rules` |
| Reservations and appointments | `get_appointment`, `get_reservation`, `list_appointments`, `list_reservation_alterations`, `list_reservations`, `present_booking_checkout` |
| Schedules | `schedule_list` |
| Skills | `get_skill`, `list_skills` |
| Tasks | `task_get`, `task_list`, `task_list_categories`, `task_list_custom_fields`, `task_list_statuses`, `task_resolve_send_target` |
| Tickets | `get_chat_history_by_ticket_id`, `get_ticket`, `get_ticket_detail`, `get_ticket_note`, `list_ticket_messages`, `list_ticket_notes`, `list_tickets`, `search_tickets` |
| Voice agents | `get_voice_agent`, `list_voice_agents` |
| Workflows | `get_workflow`, `get_workflow_outline`, `get_workflow_resource_references`, `get_workflow_schema`, `get_workflow_step`, `get_workflow_step_references`, `get_workflow_step_schema`, `list_workflow_execution_events`, `list_workflow_executions`, `list_workflow_folders`, `list_workflows`, `preview_workflow_clone`, `preview_workflow_edits` |
| Workspaces | `list_inbox_types`, `list_inboxes`, `list_workspace_senders`, `list_workspace_users`, `list_workspace_whatsapp_templates`, `list_workspaces`, `search_workspace_users` |

## Knowledge, booking, and web tools

These tools come from Conduit's knowledge service and appear in `search_tools` alongside the tools above.

| Class | Tools |
| - | - |
| Sensitive write | `book_appointment`, `cancel_appointment`, `confirm_booking`, `delete_knowledge`, `delete_source`, `reschedule_appointment` |
| Write | `bulk_set_knowledge_scope`, `create_booking_link`, `create_directory`, `create_knowledge`, `edit_knowledge`, `ingest_file`, `ingest_link`, `ingest_structured`, `move_directory_contents`, `move_knowledge`, `rename_directory`, `set_knowledge_scope` |
| Read | `find_similar_pages`, `get_appointments`, `get_booking_calendar_availability`, `get_knowledge`, `get_knowledge_scope_job`, `get_schedule`, `health_check`, `knowledge_search`, `list_knowledge`, `semantic_knowledge_search`, `web_answer`, `web_search` |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.