GoClaw security and guardrails
Non-negotiable rules
- Derive actor, SaaS, AppAccount, role, and location context server-side.
- Use the same secured APIs/stored procedures as other application surfaces.
- Resolve AI-readable context before model invocation.
- Require action-specific permission and approval where configured.
- Do not expose hidden/encrypted fields merely because an AI is acting.
- Do not allow direct SQL or legacy helper paths to bypass Inbox/action governance.
- Record meaningful planning, approval, execution, and failure evidence.
Principle
A GoClaw can be more capable than a normal screen, but it cannot be more authorized than the identity and capabilities granted to it.