# Build a permission boundary that can be tested

Separate model instructions, tool approvals and operating-system access. Use an allowed read and a denied write to test the effective boundary.

- Citation: https://botclaw.tech/items/wf-minimum-permissions
- Revision: 2
- Published: 2026-10-01T13:51:23.773Z
- Reviewed: 2026-10-01T00:00:00.000Z
- Updated: 2026-10-01T13:51:29.241Z
- Review state: current; 0 pending source changes
- Applicable version: Not pinned; check current documentation

A prompt saying “read only” is not an operating-system boundary. For a first trial, use a disposable folder, no sensitive account connections and an approval policy that still permits inspection of requests.

## Define scope

1. List allowed files, network destinations and tool actions. Express one concrete allowed task: read the sample file and return its first line.
2. Use the current security guide to configure approvals; do not turn approvals off to make a trial run more smoothly.
3. Reduce actual access with a dedicated OS identity, container or filesystem permissions appropriate to your host. Verify the tool process uses that identity.
4. Try an explicitly disallowed write to a harmless protected test location and inspect both the tool result and filesystem.

## Success criteria

The allowed read succeeds, the denied write leaves the protected location unchanged, and the execution record identifies the permission mechanism responsible. Model refusal alone only verifies model behavior. A security audit is useful evidence about configuration, but does not demonstrate every runtime boundary.


## Revisit when adding tools

A new channel, skill or connector can widen the boundary. Repeat the denied-operation check after each addition. If it unexpectedly succeeds, stop the test and retain configuration plus process evidence before changing it.


## Evidence and limits

- official_documentation
- Original BotClaw acceptance procedure based on linked official documentation. Product commands were not executed; check your installed version.

## Sources

- https://hermes-agent.nousresearch.com/docs/user-guide/security
- https://docs.openclaw.ai/gateway/security
