Chat combines three decisions: what the conversation is about, which tools your role can use, and whether this session is read-oriented or can write.
Scope the conversation
Choose the narrowest scope that contains the work:
Changing scope returns the conversation to Ask mode. Verify the scope shown in the workspace before requesting a material action.
Choose a mode
Ask mode is read-oriented. It exposes only tools allowed for read work. If a protected read needs approval, Forge can still present an approval request.
Full access can expose both read and write tools allowed by your role and the current surface. It does not override role permissions, Availability, connection state, or provider support.
Review approvals
Some interactive tools are configured to require a fresh decision. When Chat pauses:
Read the request
Confirm the system, tool, intended target, and effect.
Check the conversation
Make sure the proposed call matches what you asked Forge to do.
Approve or deny
Approval allows that specific call. Denying it does not end the conversation; explain the safer alternative and continue.
Several requests can be pending at once. Review each one separately.
A system must be connected, available in the current scope, enabled for Chat, and allowed by your role. Account-scoped tools may also need a valid account mapping. The tools shown in Chat are the intersection of those controls.
Approval policies apply to interactive work. Background surfaces such as Custom Agents use Availability because no person is present to answer an approval prompt.
Administrators can configure these boundaries in Systems and integrations, Availability and approvals, and Roles and permissions.