Skip to main content

Choose tools and destinations for agent work

Choose approved accounts, tools, and output destinations for your Octavus Agents based on the data they handle and the actions they perform.

A correct report can still end up in the wrong place. Decide where your Octavus Agent may process information and save its work.

Discuss the examples here with the people responsible for approving tools and publishing. Document your agreed rules in the Handbook before asking the Agent to use a service or publish a file.

Specify the account, data, and action

“Use our document tool” leaves several questions open. Which account? Which workspace? May the Agent read documents, edit them, or invite other people?

For each job, ask your Agent to propose:

  • Account: the Agent's approved work identity and workspace.
  • Data: what information it may process there.
  • Actions: what it may read, change, upload, or send.
  • Destination: where results belong and who may access them.
  • Exceptions: who approves a new tool, account, or wider access.

Prefer the Agent's own work identity with narrowly scoped access over your personal account. Grant access through your company's approved process, then ask the Agent to connect. Service permissions belong to the account being used. A connector does not narrow an account's access to match your policy.

Credential handling already has a baseline: the vault is dedicated secure storage, and Agents are instructed not to expose passwords, keys, or one-time codes in replies. You need not recreate those instructions.

Allow useful freedom where it fits

A public-research Agent could browse unfamiliar websites without asking about every source. That gives it room to investigate. You might still require approval before it creates an account, accepts terms, starts a trial, or uploads company information.

An Agent preparing employee compensation reports could be limited to named internal sources and an approved reporting tool, with no uploads to new services. That reduces flexibility and may require more human help, but keeps the intended processing locations explicit.

The choice depends on the role and data. Specify the approved data types for each tool, including whether it may handle confidential documents.

Cover every route the Agent can use: connectors, skills, and its computer. If a connector fails, switching to the browser should preserve the same account, data, and action limits. A new route must not become a workaround for a denied permission.

Settings > Capabilities can disable individual built-in capabilities. It does not block equivalent actions through connectors, skills, or the computer. Use actual service and account permissions alongside Handbook instructions.

Choose the destination before creating the output

OutputPossible company rule
Approved public event flyerPublish through an approved public destination after the required content approval.
Internal planning reportSave in the approved team workspace with access limited to the intended readers.
Confidential personnel summarySave only in the designated restricted folder; share with authorized recipients.

Choose destinations based on the information in the output and who is authorized to see it. Even a short summary can contain sensitive details.

Built-in asset links and hosted pages are public to anyone with the URL. Use an approved access-controlled destination for internal or restricted work. People with the link can still open an unlisted or unindexed page. Use a destination that checks who is allowed access before showing the content.

If the destination is unclear, have the Agent pause before uploading. Approval to write a report does not automatically approve public hosting. Specify who approves public publishing and later replacements or removals.

Write cleanup instructions you can check

For controlled outputs, name which temporary files should be removed, when, and who retains the final version. Ask the Agent to report what it removed and what it could not access. Deleting a working file does not establish erasure from history, memory, backups, or external providers.

Ask the Agent to propose updates to existing Handbook guidance and wait for human approval before saving. Keep rules readable by affected Agents without embedding sensitive source data.

Ask your Agent to help

Read https://octavus.ai/support/agent-policies/choose-tools-and-output-destinations and search our existing Handbook guidance. Ask me which accounts, tools, data types, actions, and destinations are approved, and who decides exceptions. Propose focused updates or a new page only where needed, including controlled-output cleanup rules. Do not connect services, change access, or upload files as part of drafting. Wait for the appropriate human's approval before saving. Then return the changed Handbook links and any unresolved permissions or actions, including account access or edits a human must handle.