Access levels
Each DigitalOcean account has an access level: Read-only and Full access. Squad refuses any agent action outside that level. You can also narrow or block single agents under Per-agent access.
Full access is the recommended level. The connect window selects it for you, and you can choose another level.
The DigitalOcean sign-in page asks you to approve full access to your account. This is expected. Squad does not narrow the sign-in. It checks every agent action against the level you chose, and it refuses actions outside that level.
What agents can do at each level
Each level opens with a short summary in plain tasks, then lists every action it adds, grouped by what the action works on. You do not need to name actions. Ask in plain words, and the agent searches for the matching action. Each action shows its name, a one-line description where the DigitalOcean action catalog has one, and its slug. The slug is the ID that agents use when they call the action.Read-only
Read-only
Agents can use 21 of the 48 DigitalOcean actions at this level:
- View domains
- View droplets
- View images
- View networks
- View records
- View tags
- View apps
- View clusters
- View databases
- View firewalls
- View keys
- View load balancers
Full access (recommended)
Full access (recommended)
Agents can use 48 of the 48 DigitalOcean actions at this level: everything in Read-only, plus:
- Create and delete clusters
- Create, update, and delete networks
- Create, update, and delete records
- Create and delete domains
- Create and delete droplets
- Create and delete firewalls
- Create and delete images
- Create and delete keys
- Create and delete load balancers
- Update resources
- Create and delete tags
- Create and delete volumes
Connect DigitalOcean
Before you start:- You need a DigitalOcean account that you can sign in to.
- Your Squad subscription must be active. Squad does not connect apps while the subscription is not active.
1
Open Integrations
Open Settings > Integrations.
2
Add an integration
On the Connected apps tab, click + Add integration.
3
Find DigitalOcean
Find DigitalOcean in the catalog and click it. You can type the name in Search the catalog….
4
Choose an access level
Under Default scope, choose an access level. This level applies to every agent.
5
Click Connect DigitalOcean
Click Connect DigitalOcean. The DigitalOcean sign-in page opens in a new tab.
6
Sign in to DigitalOcean
Sign in to DigitalOcean and approve the request.
Change the access level
- Under YOUR CONNECTIONS, find the DigitalOcean account.
- Open the account menu (⋯) and click Manage scope.
- Under Default scope, choose the new level.
- Click Save access.
Set access for one agent
Every agent uses the account’s level unless you set something else for it. You can narrow one agent to a lower level, or block it.- Under YOUR CONNECTIONS, open the account menu (⋯) on the DigitalOcean account.
- Click Manage scope.
- Under Per-agent access, find the agent.
- Choose the Default option to follow the account’s level, choose a lower level, or choose No access.
- Click Save access.
Use more than one DigitalOcean account
Click + Account on the DigitalOcean card to connect another account. Agents use the primary account unless they are asked to use a specific one.- After you click + Account, follow the connect steps above.
- Each account has its own access level.
- The first account you connect becomes the primary account. It shows ★ PRIMARY.
- To change the primary account, open the account menu (⋯) and click Make primary.
- To tell accounts apart, open the account menu (⋯) and click Rename.
Reconnect or disconnect
Reconnect when the connection has expired, or when you need to change what the account can reach on the DigitalOcean side:- Open the account menu (⋯) and click Reconnect.
- Click Reauthorize on DigitalOcean.
- Sign in to DigitalOcean and approve the request.
Costs
DigitalOcean actions do not use Squad credits. Connected apps never use credits. For what does use credits, see What Squad costs.Troubleshooting
An agent reports that an action is not allowed on this account.- Cause: the action is outside the account’s access level, or outside the level you set for that agent.
- Fix: choose a higher level in Manage scope, or change the agent’s row under Per-agent access.
- Cause: the agent is set to No access under Per-agent access, or the account is not connected.
- Fix: open Manage scope and change the agent’s row. If the account is missing, connect it again.
- Cause: your Squad subscription is not active.
- Fix: resubscribe. See Manage your subscription.
- Cause: the sign-in for that account is no longer valid.
- Fix: use Reconnect on the account.
Common questions
Can I limit what agents can do in DigitalOcean?
Can I limit what agents can do in DigitalOcean?
Each DigitalOcean account has an access level: Read-only and Full access. Squad refuses any agent action outside that level. You can also narrow or block single agents under Per-agent access.
Can I connect more than one DigitalOcean account?
Can I connect more than one DigitalOcean account?
Click + Account on the DigitalOcean card to connect another account. Agents use the primary account unless they are asked to use a specific one.
How do I disconnect DigitalOcean?
How do I disconnect DigitalOcean?
Open the account menu (⋯) on the DigitalOcean account and click Disconnect. Agents lose access to that account at once.
Related pages
Connect apps
Add an MCP server or an API key
Use this when an action you need is not in this app.