Before you start
- Only tenant Owners and Admins can connect, reconnect, or revoke an agent integration. The Connect, Reconnect, and Remove buttons are disabled for other roles.
- Agent integrations must be enabled for your workspace. If they are not, the settings section shows Agent integrations are not enabled in this environment.
- Allow pop-ups for Control in your browser. The provider consent screen opens in a new window.
Connect Slack or Gmail
- Open .
- On the Slack or Gmail card, choose Connect. A new window opens the provider’s hosted consent screen.
- Sign in to the intended workspace account and approve the permissions.
- Return to Control. The card updates to Connected as soon as the provider confirms the connection.
The connection is workspace-scoped: it belongs to the Control tenant, not to the individual user who created it. Any
Control user with access to the workspace can trigger agents that use it, subject to the agent’s own tool policy.
Permissions granted
Control uses Nango to run the OAuth flow and store credentials. The provider scopes you approve determine what agents can read and propose:
The exact scope list is shown by the provider on the consent screen. Review it before approving.
Reconnect
Providers can invalidate a token if the granting user’s access changes or if a workspace admin revokes it. When that happens the card shows Reconnect required.- Open .
- Choose the reconnect icon on the affected connection.
- Complete the provider consent screen in the new window.
Revoke
Remove a connection when you no longer want agents to read from that workspace account, or as part of offboarding.- Open .
- Choose the remove icon on the connection.
- Confirm the prompt.
Revoking an agent integration does not affect any accounting or CRM data source. Slack and Gmail connections are
managed separately from the connections used for financial data imports.
How agents use the connection
Agents that need Slack or Gmail context call read-only tools through Control’s MCP server. Anything that would send a message, post to a channel, or deliver an email is exposed to the agent as a proposal only:- The agent submits a proposal with the exact payload it wants to send.
- Control records the proposal and holds it in the approval queue.
- An Owner or Admin reviews the payload and approves or rejects it.
- Only after approval does Control deliver the message or draft through the connected account.
Troubleshooting
- The Connect button is disabled. Your role does not have permission. Ask an Owner or Admin to connect the integration.
- Nothing happened after Connect. Check that your browser allowed the pop-up window for Control, then try again.
- The connection flow did not complete. The intent expires after 30 minutes. Start again from Connect.
- The card shows Reconnect required. The provider invalidated the token. Use Reconnect to reauthorize.
- Agent integrations are not enabled in this environment. The feature flag is off for your workspace. Contact Control support to request enablement.