Build a permission boundary that can be tested
Separate model instructions, tool approvals and operating-system access. Use an allowed read and a denied write to test the effective boundary.
- Published
- Oct 1, 2026
- Reviewed
- Oct 1, 2026
- Content updated
- Oct 1, 2026
- Applicable version
- Not pinned; check current documentation
- Platforms
- Isolated test environment
Before you start
- A disposable workspace and a separate test identity where possible
A prompt saying “read only” is not an operating-system boundary. For a first trial, use a disposable folder, no sensitive account connections and an approval policy that still permits inspection of requests.
Define scope
- List allowed files, network destinations and tool actions. Express one concrete allowed task: read the sample file and return its first line.
- Use the current security guide to configure approvals; do not turn approvals off to make a trial run more smoothly.
- Reduce actual access with a dedicated OS identity, container or filesystem permissions appropriate to your host. Verify the tool process uses that identity.
- Try an explicitly disallowed write to a harmless protected test location and inspect both the tool result and filesystem.
Success criteria
The allowed read succeeds, the denied write leaves the protected location unchanged, and the execution record identifies the permission mechanism responsible. Model refusal alone only verifies model behavior. A security audit is useful evidence about configuration, but does not demonstrate every runtime boundary.
Revisit when adding tools
A new channel, skill or connector can widen the boundary. Repeat the denied-operation check after each addition. If it unexpectedly succeeds, stop the test and retain configuration plus process evidence before changing it.
Evidence and limits
Official documentation checked
- Original BotClaw acceptance procedure based on linked official documentation. Product commands were not executed; check your installed version.
Sources
Cite or read with tools
https://botclaw.tech/items/wf-minimum-permissions