Claude, explained

The Claude connector permissions guide

Before you connect Claude to your inbox, calendar or files, there's one setting worth two minutes of your time. It decides how much control you're actually handing over.

The three permission levels

Always Allow

No prompt, no pause. Reserved for actions that can't cause any real harm, like reading an email or checking your calendar.

Needs Approval

Claude shows you exactly what it wants to do and waits for a yes. The right setting for anything that sends, changes or shares something.

Blocked

Off the table entirely, no matter what's asked. Use it for anything you never want an AI deciding on, like permanent deletion.

Setting Up Connectors

It's easy to think of a connector as a way for Claude to "look things up" — read your inbox, check your calendar, pull a file from Drive. That's part of it, but it's not the whole picture.

Once connected, Claude doesn't just read your data. Depending on the tool, it can act on it too: drafting an email, editing a calendar event, updating a record, or deleting a file. Some actions are reversible and low stakes. Others are not, which is exactly why the permission setting exists.

Try itNone of this is a reason to avoid connectors. It's the reason to spend two minutes deciding what each one is allowed to do, before you let it get to work.

The tools will vary depending on what you've connected, but the pattern doesn't change. Reading is low risk. Anything that changes, moves or removes something real is where you want your hand still on the wheel.

  • Gmail — reading & searching: Always allow
  • Gmail — drafting a reply: Always allow
  • Gmail — email send: Needs approval
  • Calendar — viewing: Always allow
  • Calendar — creating, moving or cancelling events: Needs approval
  • Drive — reading files: Always allow
  • Drive — deleting files: Blocked
  • Notion — reading: Always allow
  • Notion — writing or updating: Needs approval
The pattern to rememberReads can lean toward Always allow, they only look, nothing changes because of them. Anything that edits, moves or deletes real data belongs on Needs approval, or Blocked if there's no reason for Claude to ever do it unsupervised.

You only need to do this once per tool. After that, it stays set until you change it.

  1. Open Settings in Claude and go to Connectors
  2. Click into the connector you want to adjust, like Gmail, Google Drive or Notion
  3. You'll see the actions grouped by type, usually read-only tools and write or delete tools
  4. Set each group, or each individual action, to Always allow, Needs approval, or Blocked
  5. Repeat for every connector you've got switched on
Try itDo this the moment you connect a new tool, before Claude starts using it. A new connector shouldn't go live until you've told it what it's allowed to touch.

You don't need to land on the perfect setup on day one. It's completely reasonable to leave most things on Needs approval to begin with, watch how Claude actually uses each connector for a week or two, and shift the ones you're comfortable with over to Always allow once you trust the pattern.

Make it a regular check-inCome back to these settings every so often, not just once. Revisit them whenever you connect something new, and give the whole list a once-over every few months.