> ## Documentation Index
> Fetch the complete documentation index at: https://dev.nickel.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions and Confirmations

> Who can connect, whose permissions apply, and which actions ask before they run

An assistant connected to Nickel can move money, so there are several checks between what you type and a payment going out: who can connect a client, whose permissions the client uses, a confirmation before every change, and your bill approval policies. This page covers each one.

## Who can connect

Only an **admin** of your Nickel organization can approve a browser sign-in or create an MCP token. Anyone else who tries to connect sees "You do not have the relevant permissions to connect apps" on the approval screen.

## Whose permissions apply

A connection acts as the person who approved it, or who created its token. Every tool call runs with that person's role, the same as if they were using the dashboard. When a role doesn't allow something, Nickel refuses the call and the assistant tells you why.

The tools a client sees also depend on what your organization uses. The Nickel Banking tools appear only when your organization has an active Nickel Banking account.

## Confirmations

Tools that only read — searching, listing, and fetching a single record — run as soon as the assistant calls them.

Every tool that changes your account asks you first. That covers moving money, like paying a bill or issuing a refund, and every other change too: creating or editing a record, sending an invoice by email, and marking an invoice or bill as paid. Before one of these runs, your client shows a confirmation that names the action and lists every value it will send, with amounts in dollars.

* **Confirm**, and the action runs.
* **Decline or cancel**, and nothing changes. The assistant is told the action was not confirmed.
* **No answer within five minutes**, and the request times out. Nothing changes.

Read the values before you confirm. The confirmation shows exactly what the assistant is about to send, which is how you catch a wrong amount or a date it guessed. The [tool reference](/mcp/tools) marks every tool that asks.

Records such as a vendor, bill, or payment appear in the confirmation by their Nickel ID, not their name. If you aren't sure which record an ID is, decline and ask the assistant. Paying a bill pays its full amount due, so that confirmation lists the bills rather than a sum.

<Note>
  Confirmations use a part of MCP called **elicitation**, which not every client supports. If yours doesn't, Nickel refuses every tool that changes your account rather than run it unconfirmed, and the assistant tells you so. Lookups still work. Use a client that supports elicitation, such as Claude Code, or make the change in the Nickel dashboard.
</Note>

Nickel also labels each tool as read-only or as one that makes changes, using MCP's standard tool hints. Some clients use these labels to ask for their own approval before calling a tool. That approval is separate from Nickel's confirmation, so you may be asked twice.

## Bill approval policies

A confirmation is your approval to *submit* an action. It doesn't bypass your organization's bill approval policy. When a bill payment or a recurring bill falls under the policy, Nickel sends it to your approvers instead of paying it, and the assistant reports it as sent for approval. Approvers approve it in the Nickel dashboard; there's no MCP tool for approving.

Your assistant can tell you in advance whether a payment will need approval, and who has to approve it.

## Where to go next

<Columns cols={2}>
  <Card title="Tool reference" href="/mcp/tools" icon="wrench">
    Every tool, with the ones that ask for confirmation marked.
  </Card>

  <Card title="Connect a client" href="/mcp/connect" icon="plug">
    Browser sign-in and API tokens, and how to disconnect.
  </Card>
</Columns>
