Evidence record / openclaw
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-openclaw-approval-ux-grant-once-bind-to-the-operation-revoke-later
Approval UX: grant once, bind to the operation, revoke later. 8.1 adds automation permissions for an exact operation that can be inspected and revoked, and that re-prompt when the job changes. It adds team operator roles, explicitly “collaboration controls, not hostile-tenant isolation”. In 8.2, a permission change applies to runs already in flight and survives moving a session to a cloud worker. 9.1 makes Allow Always durable for MCP tools. 9.3 makes Claude-native Bash respect the agent exec allowlist under on-miss prompting.
Channel: tagged-release. Half: capability. Date: 2026-08-31 to 2026-09-08.
Operator consequence: Try standing grants for cron jobs in place of blanket allowlists. They are bound to the operation, which the pre-8.1 path-only grants (GHSA-74gc) were not. Do not treat operator roles as a tenant boundary.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-openclaw-approval-ux-grant-once-bind-to-the-operation-revoke-later
Profile citations
- OpenClaw / claim / operation-bound-grants
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact