Perplexity Computer is adding a more granular safety control for its integrations: users can now set each connector tool to Allow, Always Ask, or Deny. The update is available on the web for all Computer users, and it is designed to make AI-driven workflows feel less like handing over the keys and more like setting clear rules for every app the agent can touch.
For anyone using an AI agent to work across Gmail, Slack, Google Drive, Notion, GitHub, or other connected services, that distinction matters. A connector is not simply a source of background context. It can be the bridge that lets Computer retrieve data from external apps and, depending on the integration and permissions granted, take actions inside them. Perplexity has also expanded Computer’s connector ecosystem through standard integrations and support for custom remote connectors using Model Context Protocol, or MCP.
The three new choices are straightforward, but they address three very different levels of comfort. Allow is the friction-free setting: Computer can use that specific connector without stopping to seek approval each time. Always Ask puts the user back in the loop for every attempted use, which is particularly useful for tools tied to personal communications, customer records, financial systems, or published content. Deny, meanwhile, blocks the connector from being used altogether.
What makes the rollout more interesting is its thread-level behavior. Users can approve a single action or permit the tool for the rest of a conversation, and recurring runs will follow the approvals made in that thread. In practical terms, someone could let Computer work freely with a low-risk research database while requiring a confirmation before it opens a Gmail or Slack connector.
That is a sensible evolution for agentic AI. The real value of systems such as Computer is their ability to go beyond answering questions: they can pull information from connected tools, assemble a report, update a workspace, or help carry a workflow from start to finish. But the same capability introduces a basic trust problem. The closer an AI gets to a person’s inbox, files, source code, calendars, and work chat, the less useful a one-size-fits-all permission model becomes.
A journalist, for instance, might be comfortable with Computer checking a read-only research repository or surfacing notes from a dedicated Notion database. That same person may want a hard stop before the agent accesses email threads containing sources, client documents in Drive, or a CMS tied to a live publication. The point is not that every connector is risky. It is that risk changes dramatically depending on the service, the data inside it, and whether the agent is merely reading information or performing a write action.
The new controls also help solve a common usability problem with permission prompts. Ask for approval too often and users start clicking through them reflexively. Ask too rarely and the AI can feel opaque or overly powerful. Perplexity’s connector-by-connector approach gives users room to draw a more realistic line: automatic access for routine, trusted tools; one-off approvals for sensitive ones; and a permanent block for services that should stay outside the agent’s reach.
That approach resembles the broader direction of enterprise AI governance. Perplexity has previously said that its enterprise controls can restrict where and how the assistant operates, including permissions that apply across a browser or only on specific domains, while sensitive actions can require approval and sessions can be reviewed through action logs. The new connector settings bring a version of that logic closer to everyday Computer use.
It is also a useful reminder that connecting an app is only the first permission decision. OAuth authorization may grant an integration access to a service, but users still need a practical way to decide how an AI may exercise that access during real work. Perplexity’s own enterprise guidance notes that administrators can enable or disable connected apps through organization permissions, while services such as Microsoft 365 may require separate administrator consent before the connector can proceed.
For heavy users, the most sensible setup will likely be mixed rather than all-or-nothing. Set Allow for low-stakes, repeatable research tools. Use Always Ask for email, team messaging, external publishing, and any system where a mistaken action would be difficult to reverse. Use Deny for connectors that are unnecessary, overly broad, or simply not worth exposing to an agent. That is not a limitation on automation – it is the kind of control that makes deeper automation easier to trust.
Discover more from GadgetBond
Subscribe to get the latest posts sent to your email.
