Skip to main content
Connectors bring the services you already use into Canvas. Once you connect a service, the Canvas Agent can use it during an investigation alongside your Honeycomb telemetry. For example, the Canvas Agent can review an incident.io timeline, check who is on-call in PagerDuty, or read your runbooks in Notion. Each connector has tools. A tool is one action that the Canvas Agent can take in the service, such as reading an incident or creating an issue. You control which tools the Canvas Agent can run with tool permissions.
Connectors work per user and per Honeycomb Team. You connect your own account, and the Canvas Agent uses the connected service as your account. Connecting a connector does not connect it for anyone else on your Honeycomb Team. If you belong to more than one Honeycomb Team, connect your account in each Team. Your tool permissions also apply only to you, in one Honeycomb Team. There are no Team-level connector controls yet.Connectors work through your account, so an automatic investigation has no connector access at all.

Available connectors

To start and follow investigations from Slack, visit Ask Canvas in Slack.

Opening the Connectors page

  • Navigate to Canvas > Connectors.
  • In a Canvas chat, select the plus (+) button, choose Connectors, then select Manage Connectors.

Adding a connector

  1. Navigate to Canvas > Connectors.
  2. Find the connector in the list. Select its name to read what the Canvas Agent can do with it and what access it needs.
  3. Select Connect.
  4. Review the access you are granting on the service’s authorization page, then approve it.
The connector shows a Connected badge once the connection succeeds.

Turning connectors on or off per investigation

Use the chat menu to control which connectors the Canvas Agent can use during an investigation:
  1. In a Canvas chat, select the plus (+) button.
  2. Choose Connectors.
  3. Use the toggle beside a connector to turn it on or off for this investigation.
The menu lists only the connectors you already connected. The toggle turns the full connector on or off. To control one tool, use tool permissions.

Reconnecting a connector

When an authorization expires or someone revokes it, the connector’s row shows a warning and its action changes to Reconnect. Select Reconnect and authorize Honeycomb again.

Disconnecting a connector

  1. Navigate to Canvas > Connectors.
  2. Find the connected connector and select Manage.
  3. Select Disconnect.
Disconnecting revokes Honeycomb’s access to that service and removes the connector from your chat menu.

What the Canvas Agent can access

The Canvas Agent authenticates to a connected service with your account. It reads only the content your own account can see in that service. The same restrictions apply to what it can write or change. Each connector’s page describes the access its authorization covers.

Managing tool permissions

Each tool in a connector has a permission that controls what the Canvas Agent does when it wants to use that tool. You can set your permissions before an investigation starts, so the Canvas Agent does not have to ask you during the investigation. A permission controls only what the Canvas Agent can do. The Canvas Agent runs a tool only when your investigation needs it.

Tool groups and defaults

Honeycomb reviews each tool and puts it in a group. Until you set a permission, each group uses its default permission: By default, GitHub allows its unreviewed tools, because the GitHub connector is read-only. For Read-only tools and Write tools, you can set one permission for the full group. For the other groups, you set each tool one at a time. A permission you set on a tool overrides the permission of its group. A permission you set on a group overrides the default.

Changing tool permissions

  1. Navigate to Canvas > Connectors.
  2. Find the connector and select Manage.
  3. Under Tool permissions, expand a group to see its tools.
  4. (Optional) To set one permission for Read-only tools or Write tools, select a permission from the menu beside the group. Select Not set to use the default again.
  5. (Optional) To set the permission for one tool, select Always allow, Ask, or Never beside the tool. A dashed outline shows the permission the tool gets from its group. To remove your setting, select the same permission again.
  6. Select Save.
Tool permissions show only for a connected connector. If you have a read-only role on your Honeycomb Team, you can see tool permissions but you cannot change them.

Honeycomb tools

The Connectors page also lists Honeycomb. Honeycomb is not a connector, because the Canvas Agent always has access to your Honeycomb data. You do not connect or disconnect Honeycomb. To set permissions for Honeycomb tools, find Honeycomb and select Manage. Honeycomb read-only tools are always allowed, because the Canvas Agent needs them to investigate. Their controls are disabled, and the Read-only tools group has no permission menu. You can set permissions for Honeycomb write tools and destructive tools, such as the tools that create boards, SLOs, and triggers. Tools that the Canvas Agent uses to build your Canvas do not show in this list. The Canvas Agent always has access to them.

Approving tool calls

When a tool’s permission is Ask, the Canvas Agent asks you to approve each call. If you did not set a permission, write tools, destructive tools, and unreviewed tools use Ask by default. When the Canvas Agent wants to run a tool that has the Ask permission:
  1. An approval prompt appears in your Canvas chat, naming the tool the Canvas Agent wants to run.
  2. Select Approve to let the call run, or Deny to stop it.
    1. (Optional) If you deny the action, you can provide a reason and tell the Canvas Agent what to do instead.
Approval covers one call, so the Canvas Agent asks again the next time it wants to run that tool. To stop the prompts for a tool, change its permission to Always allow. To learn more, visit Managing tool permissions. Connectors need your account, so the Canvas Agent has no connector access during an automatic investigation.

Requesting a connector

  1. Navigate to Canvas > Connectors.
  2. Select Request a connector.
  3. Name the service, and describe what the Canvas Agent would need from it during an investigation.
  4. Select Send Request.