Permissions cheat sheet
Look up which permission OpenClaw Control Plane (OCC) checks for a public
operation. A permission is an exact action and resourceKind; a Role grants it
through an AccessBinding. Missing grants are denied, matching Restrictions
override grants, and one action never implies another. See
Authorization for the full policy.
Actions
| Action | What it permits |
|---|---|
create |
Create a resource in its parent Installation or Namespace. |
read |
Read a resource or include it in a list; Secret reads return metadata, not values. |
update |
Change a resource or its credential. |
delete |
Request deletion of the exact resource. |
deploy |
Admit a new Agent revision. |
operate |
Stop an Agent, provision its runtime credentials, write its workspace files, or use a bound Secret or credential source. |
administer |
Run Installation administration or access the exact Agent’s native admin UI. It does not imply read, deploy, or other actions. |
Resources and scopes
This is the set checked by current public operations. Fresh native IAM bootstrap grants these pairs to the human administrator and the non-Agent bootstrap service principal. Rerunning bootstrap does not add missing permissions to existing Roles.
| Resource kind | Actions | Scope checked |
|---|---|---|
installation |
read, administer |
Singleton Installation. |
namespace |
create, read, delete |
Installation for create; exact Namespace otherwise. |
configuration |
create, read, update, delete |
Namespace for create; exact Configuration otherwise. |
preset |
create, read, update, delete |
Namespace for create; exact Preset otherwise. |
service_account |
create, read, update, delete |
Namespace for create; exact ServiceAccount otherwise. Credential creation also uses update. |
secret |
create, read, update, delete, operate |
Namespace collection for create; list needs Namespace read and returns only Secrets with exact read. Other actions target the exact Secret. operate is checked when a Secret is bound or used. |
credential_source |
create, read, delete, operate |
Namespace collection for create; list needs Namespace read and returns only sources with exact read. Other actions target the exact source. operate is checked when a source is bound or deployed. |
agent |
create, read, update, delete, deploy, operate, administer |
Namespace for create; exact Agent otherwise. Native admin requires a human session. |
agent_revision |
read |
Exact AgentRevision; deployment-status reads use this permission too. |
Namespace, Preset, Agent, ServiceAccount, AgentRevision, Secret, and credential
source lists check each returned resource. Listing Agents or ServiceAccounts also requires namespace:read;
listing AgentRevisions also requires agent:read on the parent. The
HTTP API reference lists exact targets and conditions for
each operation.
Sign-in, sign-out, and session lookup use session rules rather than resource permissions. Installation bootstrap and account creation require a human session; service-key administration also accepts an authorized Installation-scoped service key. A Namespace-scoped key cannot access another Namespace or Installation endpoints. An Installation-scoped key still needs its principal’s own grants; it does not inherit the issuer’s. See service key scope.
Additional checks
- Channel directory lookup
requires
agent:createin the Namespace, oragent:updateorconfiguration:updateon the exact edit target, plussecret:operateon the exact same-Namespace Secret used for the lookup. - Model discovery for Agent creation requires
agent:createin the exact Namespace. The supplied API key or service account token is used transiently; no resource is created. - Create, update, and
deploy an Agent also
require
configuration:read,service_account:readfor current or new associations,secret:operatefor bound Secrets, andcredential_source:operatefor a bound credential source. At deployment the Agent’s own service principal also needssecret:operateon each bound Secret andcredential_source:operateon its source. - Registering a credential source
also requires
secret:operateon each referenced Secret. - Create or
update a Configuration
with Secret bindings requires
secret:operateon each bound Secret. - Adopting an existing Kubernetes namespace also
requires
installation:administer. - Provisioning Agent runtime credentials
requires both
agent:operateandagent:read. - A first Agent deployment
also requires exact-Agent
readandoperatewhen the selected Compute Driver must create missing generated transport credentials. - Namespace IAM operations require
installation:administerandnamespace:read. Creating an AccessBinding also requiresreadon its exact target. Listing Backends usesinstallation:administer; Backend and IAM policy objects have no separate permission resource kinds. - Reading the observability destination uses
installation:administer. The configured external service enforces its own access.
The Namespace policy API accepts
every action name on agent, agent_revision, configuration,
credential_source, preset, secret, and service_account, including
combinations no current operation checks. On namespace it accepts only read.
It can bind an existing human Principal or a Namespace-local ServicePrincipal
to an existing exact resource, including the path Namespace itself. Exact
Namespace access does not grant access to child resources.
It cannot create Installation or Namespace-wide grants, including the collection
permission needed to create resources. Existing Namespace-wide and Group
bindings can still be listed or deleted. Groups and Restrictions cannot be
managed through this API.
