GoClaw secure context assembly
Context assembly
GoClaw context is not a broad scrape of tenant data. It is assembled under the acting identity’s resolved permissions and may include the Inbox source, record graph, activity chain, conversations, files, calendar data, knowledge, and RAG results that are individually permitted.
AI rule
The model receives an already-permitted context set. Prompt instructions are not the security boundary.
Freshness
Context should carry the relevant Inbox ActivityVersion or equivalent freshness marker so later approval/execution can detect whether the business context changed after planning.