# Control app access The Apps tab distinguishes connecting a service from allowing the agent to use it. The per-app **Agent access** switch pauses use while keeping the connection available for later. **Launch preview:** hosted app-tool execution is not publicly enabled yet. These controls describe the desktop connection workflow; turning a switch on does not bypass account, provider, or release availability limits. ## Pause an app 1. Open **Settings → Apps** and locate the connected service in the App Store. 2. Open its details if you want to review its available tools first. 3. Turn **Agent access** off. 4. Confirm the row says **Connected · agent access off**, or the details explain that the connection is kept and the agent will not use the app. This is useful when you want to focus on one service, temporarily exclude a work account, or stop a connected app from participating in new tasks without signing out of it. ## When the change applies The access preference is checked before the next app action. If disabled, that action is refused and the agent is told the app is turned off in Apps. The setting also covers supported app-data access used by previews built in the notch. Do not treat the switch as an undo button. It cannot retract a message already sent, reverse a completed edit, or guarantee cancellation of an external request that has already started. Stop the current task when appropriate and inspect the destination service if an action may be in progress. ## Restore access Turn Agent access back on when you want to use the service again. The saved connection remains, so a fresh sign-in is normally unnecessary unless the provider expired or revoked it. Check the row's status and try a small read request before a write. App access is enabled by default for connected apps. Review it after connecting a new service rather than assuming every connection starts paused. ## Choose the right control Use **Agent access off** to pause Nock's use of a service while keeping its connection. Use **Disconnect** to remove the connection from Nock's connection list. Use the provider's security settings to review or revoke the authorization held by that integration. These controls are separate from operating-system permissions such as microphone or screen access. Disabling an email connection does not change screen permissions, and removing screen permissions does not disconnect email. For an app that says connected but fails, check Agent access first, then account availability and provider permissions. Avoid asking the agent to work around a disabled switch. See [Disconnect apps](/nock/disconnect-apps), [App connections](/nock/app-connections), and [Privacy and data](/nock/privacy).