Skip to content
Vendor.sh

Theme

Palette

Your own colour

Saved for this browser, on every page.

Useful actions, with the door only as wide as the job.

Give an agent a tool and it can search your sources, read a page, open an issue or call your own service. You choose exactly which agent may call which tool, and every call is written down.

Tool access
Which agent may call which tool
Which agent may call which tool knowledge web_search web_fetch linear
Support triage Allowed Not allowed Not allowed Allowed
Invoice parser Allowed Not allowed Not allowed Not allowed
Research assistant Allowed Allowed Allowed Not allowed
Contract review Allowed Not allowed Allowed Not allowed

Illustrative. Unticked means unreachable — an agent cannot see a tool it was not given.

Four kinds of tool

Start with what is built in. Reach your own systems when you need to.

Built in

Ready on day one

web_search · web_fetch · file_search · vector_similarity

HTTP

Your own endpoints

Describe a request once; the agent fills only the inputs you expose.

MCP

Model Context Protocol servers

Connect a server and choose which of its tools the workspace may use.

Code

Small, bounded functions

For the transformation that is easier to write than to prompt.

Boundaries

A tool call can reach what you allowed, and nothing next to it.

  • Outbound calls go through a restricted URL policy.
  • Connection credentials stay outside workflow content.
  • Every call is logged and scoped to the workspace.
  • A run that returns content never returns the secret it used.
Tool calls · run_8f2c Example data
Time Tool Result Detail
14:02:11 file_search allowed 3 sources · 212 ms
14:02:12 linear.create_issue allowed via connection “Linear” · 408 ms
14:02:12 http_call refused address not permitted by URL policy
14:02:13 crm.update refused tool not allowed for this agent

Illustrative. A refused call is recorded with its reason, like an allowed one.

Giving an agent a tool

Four steps from “it should be able to” to a logged call.

  1. 01

    Pick or connect the tool

    Use a built-in tool, describe an HTTP endpoint, or connect an MCP server.

    Tools → New tool

  2. 02

    Attach a connection

    The account it acts as lives in the workspace, never in the prompt.

    Tools → Connection

  3. 03

    Allow it per agent

    Tick the agents that may call it. The rest cannot see it.

    Agent → Allowed tools

  4. 04

    Run it and read the log

    Try the agent, then check each call, its result and its latency.

    Traces

Give an agent exactly the reach the job needs.

Connect a tool, allow it per agent, and read every call it makes.

No card required · Cancel anytime