OpenClaw EnterpriseDOCSGitHub

Permissions cheat sheet

Look up which permission OpenClaw Control Plane (OCC) checks for a public operation. A permission is an exact action and resourceKind; a Role grants it through an AccessBinding. Missing grants are denied, matching Restrictions override grants, and one action never implies another. See Authorization for the full policy.

Actions

Action What it permits
create Create a resource in its parent Installation or Namespace.
read Read a resource or include it in a list; Secret reads return metadata, not values.
update Change a resource or its credential.
delete Request deletion of the exact resource.
deploy Admit a new Agent revision.
operate Stop an Agent, provision its runtime credentials, write its workspace files, or use a bound Secret or credential source.
administer Run Installation administration or access the exact Agent’s native admin UI. It does not imply read, deploy, or other actions.

Resources and scopes

This is the set checked by current public operations. Fresh native IAM bootstrap grants these pairs to the human administrator and the non-Agent bootstrap service principal. Rerunning bootstrap does not add missing permissions to existing Roles.

Resource kind Actions Scope checked
installation read, administer Singleton Installation.
namespace create, read, delete Installation for create; exact Namespace otherwise.
configuration create, read, update, delete Namespace for create; exact Configuration otherwise.
preset create, read, update, delete Namespace for create; exact Preset otherwise.
service_account create, read, update, delete Namespace for create; exact ServiceAccount otherwise. Credential creation also uses update.
secret create, read, update, delete, operate Namespace collection for create; list needs Namespace read and returns only Secrets with exact read. Other actions target the exact Secret. operate is checked when a Secret is bound or used.
credential_source create, read, delete, operate Namespace collection for create; list needs Namespace read and returns only sources with exact read. Other actions target the exact source. operate is checked when a source is bound or deployed.
agent create, read, update, delete, deploy, operate, administer Namespace for create; exact Agent otherwise. Native admin requires a human session.
agent_revision read Exact AgentRevision; deployment-status reads use this permission too.

Namespace, Preset, Agent, ServiceAccount, AgentRevision, Secret, and credential source lists check each returned resource. Listing Agents or ServiceAccounts also requires namespace:read; listing AgentRevisions also requires agent:read on the parent. The HTTP API reference lists exact targets and conditions for each operation.

Sign-in, sign-out, and session lookup use session rules rather than resource permissions. Installation bootstrap and account creation require a human session; service-key administration also accepts an authorized Installation-scoped service key. A Namespace-scoped key cannot access another Namespace or Installation endpoints. An Installation-scoped key still needs its principal’s own grants; it does not inherit the issuer’s. See service key scope.

Additional checks

The Namespace policy API accepts every action name on agent, agent_revision, configuration, credential_source, preset, secret, and service_account, including combinations no current operation checks. On namespace it accepts only read. It can bind an existing human Principal or a Namespace-local ServicePrincipal to an existing exact resource, including the path Namespace itself. Exact Namespace access does not grant access to child resources. It cannot create Installation or Namespace-wide grants, including the collection permission needed to create resources. Existing Namespace-wide and Group bindings can still be listed or deleted. Groups and Restrictions cannot be managed through this API.

Search documentation