Available connectors
To start and follow investigations from Slack, visit Ask Canvas in Slack.
Opening the Connectors page
- Navigate to Canvas > Connectors.
- In a Canvas chat, select the plus (
+) button, choose Connectors, then select Manage Connectors.
Adding a connector
- Navigate to Canvas > Connectors.
- Find the connector in the list. Select its name to read what the Canvas Agent can do with it and what access it needs.
- Select Connect.
- Review the access you are granting on the service’s authorization page, then approve it.
Turning connectors on or off per investigation
Use the chat menu to control which connectors the Canvas Agent can use during an investigation:- In a Canvas chat, select the plus (
+) button. - Choose Connectors.
- Use the toggle beside a connector to turn it on or off for this investigation.
Reconnecting a connector
When an authorization expires or someone revokes it, the connector’s row shows a warning and its action changes to Reconnect. Select Reconnect and authorize Honeycomb again.Disconnecting a connector
- Navigate to Canvas > Connectors.
- Find the connected connector and select Manage.
- Select Disconnect.
What the Canvas Agent can access
The Canvas Agent authenticates to a connected service with your account. It reads only the content your own account can see in that service. The same restrictions apply to what it can write or change. Each connector’s page describes the access its authorization covers.Managing tool permissions
Each tool in a connector has a permission that controls what the Canvas Agent does when it wants to use that tool. You can set your permissions before an investigation starts, so the Canvas Agent does not have to ask you during the investigation.
A permission controls only what the Canvas Agent can do.
The Canvas Agent runs a tool only when your investigation needs it.
Tool groups and defaults
Honeycomb reviews each tool and puts it in a group. Until you set a permission, each group uses its default permission:
By default, GitHub allows its unreviewed tools, because the GitHub connector is read-only.
For Read-only tools and Write tools, you can set one permission for the full group.
For the other groups, you set each tool one at a time.
A permission you set on a tool overrides the permission of its group.
A permission you set on a group overrides the default.
Changing tool permissions
- Navigate to Canvas > Connectors.
- Find the connector and select Manage.
- Under Tool permissions, expand a group to see its tools.
- (Optional) To set one permission for Read-only tools or Write tools, select a permission from the menu beside the group. Select Not set to use the default again.
- (Optional) To set the permission for one tool, select Always allow, Ask, or Never beside the tool. A dashed outline shows the permission the tool gets from its group. To remove your setting, select the same permission again.
- Select Save.
Honeycomb tools
The Connectors page also lists Honeycomb. Honeycomb is not a connector, because the Canvas Agent always has access to your Honeycomb data. You do not connect or disconnect Honeycomb. To set permissions for Honeycomb tools, find Honeycomb and select Manage. Honeycomb read-only tools are always allowed, because the Canvas Agent needs them to investigate. Their controls are disabled, and the Read-only tools group has no permission menu. You can set permissions for Honeycomb write tools and destructive tools, such as the tools that create boards, SLOs, and triggers. Tools that the Canvas Agent uses to build your Canvas do not show in this list. The Canvas Agent always has access to them.Approving tool calls
When a tool’s permission is Ask, the Canvas Agent asks you to approve each call. If you did not set a permission, write tools, destructive tools, and unreviewed tools use Ask by default. When the Canvas Agent wants to run a tool that has the Ask permission:- An approval prompt appears in your Canvas chat, naming the tool the Canvas Agent wants to run.
- Select Approve to let the call run, or Deny to stop it.
- (Optional) If you deny the action, you can provide a reason and tell the Canvas Agent what to do instead.
Requesting a connector
- Navigate to Canvas > Connectors.
- Select Request a connector.
- Name the service, and describe what the Canvas Agent would need from it during an investigation.
- Select Send Request.