Apps and tools

Give each bot the apps it needs, and nothing more

Connected apps in Brainwrite give bots secure tools for services like Gmail, GitHub, Slack and Notion, authorised through OAuth in your own browser via Composio. The official app sets this up automatically, so there is no key to paste. OAuth tokens stay with Composio, never in prompts, and you choose per bot whether it gets all of an app's tools, an exact list, or none.

Follow up after a call

Find my last email thread with Priya at Northwind Studio, draft a follow-up with the three action items, and add them to Notion.

Your Chief of Staff put a team on it

  • Nova· Chief of Staff
  • Dash· Inbox triager
  • Sage· Reply drafter
  • Found Tuesday's thread in Gmail (work).
  • Drafted a follow-up listing the 3 action items.
  • Prepared 3 Notion tasks under Northwind Studio.

Done1 email and 3 Notion tasks to approve: waiting for your yes.

An illustrated example. Your team works on your own files and apps.
A man at a standing desk works with AI agents Dash and Atlas beside a row of colourful app tiles on the desk.
DashOperations3 apps connected
AtlasResearchRead-only access
NovaChief of Staff
9:02 am

Follow up after a call: done. One thing waits for you.

  1. 1Found Tuesday's thread in Gmail (work).
  2. 2Drafted a follow-up listing the 3 action items.
  3. 3Prepared 3 Notion tasks under Northwind Studio.
3 bots on this job
1 email and 3 Notion tasks to approveWaiting for your yes

See it in the app

Connected apps in Brainwrite.

The Apps catalog: Slack, GitHub, Gmail, Google Calendar, Sheets, Docs, Drive, Notion, Linear, Sentry, PostHog and Discord, each with Connect.

Why it matters

On your own, with a chatbot, and with Brainwrite.

Doing it yourselfA single chatbotBrainwrite
Getting data inCopy it from each appPaste it into the chatBots call the app's tools through your OAuth connection
Who can do whatYou are the access controlDepends on the product's connectorsPer bot: all tools, an exact list, or none
Work and personal accountsSign out and back inDepends on the productUp to five labelled accounts per app; the bot must pick one
Removing accessChange passwordsDisconnect in the productDisconnect revokes access at the service itself

How it works

How Connected apps works.

  1. 01

    Open Connected apps

    Choose Connected apps in the sidebar and search for the service.

  2. 02

    Connect and label

    Choose Connect, or Add account if you already have one, and give it a label such as work, personal or client-acme.

  3. 03

    Authorise in your browser

    Finish the OAuth sign-in in the browser window that opens, then return to the app.

  4. 04

    Set per-bot grants

    In a bot's settings under Connected apps, choose all tools, an exact list of tools, or no tools for each service.

  5. 05

    Ask the bot

    Ask the bot to use the service. Risky actions still reach you as approval cards.

Good to know

The details.

Several accounts per app

Connect up to five labelled accounts per app. When more than one could run an action, the bot must pick one explicitly; a new sign-in never silently replaces the old one.

Grants cover tools, not accounts

A grant says which tools a bot may call on a service and covers every account of that service. To keep a bot away from one account, use a separate installation.

Imported bots start with nothing

Imported bots and shared packages always land with no grants, so a shared persona cannot reach your Gmail on its first turn.

Ungranted tools are never offered

A tool a bot is not granted is never shown to the model, and every allow and deny is written to the decision log.

Disconnect means revoke

Disconnecting revokes that account's access at the service, not just in the app. Other accounts for the same app stay connected.

The edges, plainly

  • X (Twitter) is not available, because X does not offer the shared sign-in the other services use.
  • Until you assign a grant, every bot keeps all tools on the apps it can see.
  • Each app is capped at five usable accounts per installation.
Full reference in the documentation

FAQ

Questions about Connected apps

Can AI agents access my Gmail?

Yes, if you connect it. Open Connected apps, search for Gmail, choose Connect and finish the OAuth sign-in in your browser. The token stays with Composio, never in a prompt. Then decide per bot whether it gets all Gmail tools, an exact list, or none.

Do I need a Composio API key to connect apps?

No. The official signed desktop app registers itself with Brainwrite's managed connected-apps service, so there is no Composio key to find or paste. A Composio project key is only needed if you deliberately run the integration yourself.

Can I connect a work and a personal Gmail account?

Yes. Connect each account separately and give it a label such as work or personal. Each app allows up to five usable accounts. When more than one account could perform an action, the bot must choose one explicitly instead of quietly using the first.

Can I post to X (Twitter) with Brainwrite?

Not through connected apps. X (Twitter) is not available yet, because X does not offer the shared sign-in that the other services use. Hundreds of other services, including Gmail, GitHub, Slack and Notion, are available.

Can I limit which app tools each AI agent can use?

Yes. In a bot's settings under Connected apps, choose per service whether the bot gets all tools, an exact list, or none. Once a bot has any grant, services missing from its list give it nothing, and ungranted tools are never offered to the model.

Give your first job to Brainwrite.

Download the app, connect the AI you already pay for, and tell your Chief of Staff what needs doing.

macOS today. Windows and Linux are coming soon.