BuildWithHQ
Canonical knowledge unit · goclaw

GoClaw security and guardrails

GoClaw inherits BuildWithHQ’s server-derived identity, tenant/location/DataRole permissions, AI-specific retrieval permissions, approval controls, secret boundaries, and audit requirements; it is never a privileged bypass.

ID: BWHQ-GOCLAW-008Status: specifiedAuthority: highgoclawsecurityguardrailspermissionsaudit

GoClaw security and guardrails

Non-negotiable rules

Principle

A GoClaw can be more capable than a normal screen, but it cannot be more authorized than the identity and capabilities granted to it.

Machine-readable source: canonical Markdown. This HTML companion exists for human reading, search indexing, and AI retrieval.