Tools
A tool is something an agent can do rather than say — search the web, write a file, open a pull request, send a Slack message. An agent's tools decide the shape of what it can be asked for.
Who can do what
| Task | User | Agent owner | Admin |
|---|---|---|---|
| Use the tools an agent already has | ✅ shared in | ✅ | ✅ |
| Add or remove an agent's tools | — as Editor | ✅ | ✅ |
| Set a tool's parameters and credentials on an agent | — as Editor | ✅ | ✅ |
| Connect the organization-wide services tools depend on | — | — | ✅ |
| Register custom tools | — | — | ✅ |
Tools are configured per agent, in Agent → Settings → Tools. Some need a connection an admin has set up first — an agent can't use the GitHub tool until GitHub is connected for the organization.
Always available
Every agent gets a core set with nothing to enable — the ones that make an agent an agent rather than a chat window:
| Web | web_search, web_fetch, web_crawl, web_download — find, read, crawl, and download from the internet |
| Files | read_file, write_file, edit_file, list_files, search_files, view_file, send_file — work in the agent's file area, including sending a finished file to you in chat |
| Documents | create_document (Markdown, text, HTML), pdf_download (fetch a PDF and read its text) |
| Shell | run — execute a command in the agent's own sandbox |
| Memory | manage_memory, search_all_memories — save and recall memories, including across the organization's other agents |
| History | search_sessions — search its own past conversations |
| Scheduling | manage_routines — create and manage its own routines |
| Product docs | search_documentation, read_documentation — read these pages, which is how an agent answers "how does Delegate do X?" |
| Self-management | update_agent_settings, update_task_state, get_user_context — adjust its own name and greeting, keep a scratchpad through a long task, and know what time it is where you are |
| People | email, request_credential, invite_user — ask you a question by email, request a secret through a secure form, or invite a colleague |
| Agents | call_agent — hand work to another agent in the organization and wait for its answer |
Connection-backed
These need an organization connection before they work:
| Tool | Needs | Does |
|---|---|---|
github | GitHub connection | Browse repos, clone, commit, push, open pull requests |
slack | Slack connection | Send messages and files, list channels and users |
gmail_send, gmail_read | Google connection | Send and search mail |
google_workspace_admin | Workspace Admin connection | List, search, create, and update users in your Google Workspace domain |
docworker | DocWorker connection | Build document knowledge bases and search them semantically |
manage_identity | — | Read and update the user and company identity |
manage_skills | — | Create and manage skills |
manage_agents | — | Create and configure other agents |
ssh | Your own credentials | Work on a remote server over persistent sessions |
Configuring a tool
Each tool has its own Parameters & Credentials on the agent. Some are configuration (a default repository, a channel); some are secrets.
Secrets are encrypted at rest, and an agent never reveals its own credentials — if you ask it to print an API key it holds, it can't. An agent can also ask you for a credential mid-task via a secure input form, which is the right way to hand one over: it goes straight into encrypted configuration rather than sitting in the conversation.
Bundles
Related tools are usually enabled as a group. See Tool bundles.
Your own tools
If the capability you need isn't here, expose it yourself — an HTTP endpoint or an MCP server your agents can call. See Custom tools, and Exposing your tools over MCP for how to build the server.
Fewer tools is often better
Every tool an agent holds is described to the model on every task. A long list costs tokens and adds ways to go wrong. Give an agent the tools its job needs and leave the rest off; make a second agent for a second job.