{"item":{"id":"wf-minimum-permissions","product":"hermes","language":"en","title":"Build a permission boundary that can be tested","summary":"Separate model instructions, tool approvals and operating-system access. Use an allowed read and a denied write to test the effective boundary.","contentType":"guide","category":"security","revision":2,"canonicalUrl":"https://botclaw.tech/items/wf-minimum-permissions","sourceUrls":["https://hermes-agent.nousresearch.com/docs/user-guide/security","https://docs.openclaw.ai/gateway/security"],"sourcePublishedAt":"2026-10-01T13:51:23.773Z","reviewedAt":"2026-10-01T00:00:00.000Z","collectedAt":"2026-10-01T13:51:23.773Z","updatedAt":"2026-10-01T13:51:29.241Z","source":{"id":"botclaw-editorial","name":"BotClaw","origin":"editorial"},"summaryMethod":"editor","applicability":{"version":null,"platforms":["Isolated test environment"],"requirements":["A disposable workspace and a separate test identity where possible"]},"verification":{"kind":"official_documentation","checkedAt":"2026-10-01T00:00:00.000Z","urls":["https://hermes-agent.nousresearch.com/docs/user-guide/security","https://docs.openclaw.ai/gateway/security"],"limitations":["Original BotClaw acceptance procedure based on linked official documentation. Product commands were not executed; check your installed version."]},"body":{"introduction":"A prompt saying “read only” is not an operating-system boundary. For a first trial, use a disposable folder, no sensitive account connections and an approval policy that still permits inspection of requests.","sections":[{"heading":"Define scope","paragraphs":[],"steps":["List allowed files, network destinations and tool actions. Express one concrete allowed task: read the sample file and return its first line.","Use the current security guide to configure approvals; do not turn approvals off to make a trial run more smoothly.","Reduce actual access with a dedicated OS identity, container or filesystem permissions appropriate to your host. Verify the tool process uses that identity.","Try an explicitly disallowed write to a harmless protected test location and inspect both the tool result and filesystem."]},{"heading":"Success criteria","paragraphs":["The allowed read succeeds, the denied write leaves the protected location unchanged, and the execution record identifies the permission mechanism responsible. Model refusal alone only verifies model behavior. A security audit is useful evidence about configuration, but does not demonstrate every runtime boundary."]},{"heading":"Revisit when adding tools","paragraphs":["A new channel, skill or connector can widen the boundary. Repeat the denied-operation check after each addition. If it unexpectedly succeeds, stop the test and retain configuration plus process evidence before changing it."]}]},"indexable":true,"supersededBy":null,"review":{"state":"current","pendingChanges":0,"policyDays":7}}}