Finding / openclaw

2026-09-21-openclaw-approval-ux-grant-once-bind-to-the-operation-revoke-later

Approval UX: grant once, bind to the operation, revoke later. 8.1 adds automation permissions for an exact operation that can be inspected and revoked, and that re-prompt when the job changes. It adds team operator roles, explicitly “collaboration controls, not hostile-tenant isolation”. In 8.2, a permission change applies to runs already in flight and survives moving a session to a cloud worker. 9.1 makes Allow Always durable for MCP tools. 9.3 makes Claude-native Bash respect the agent exec allowlist under on-miss prompting.

Channel: tagged-release. Half: capability. Date: 2026-08-31 to 2026-09-08.

Operator consequence: Try standing grants for cron jobs in place of blanket allowlists. They are bound to the operation, which the pre-8.1 path-only grants (GHSA-74gc) were not. Do not treat operator roles as a tenant boundary.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-openclaw-approval-ux-grant-once-bind-to-the-operation-revoke-later

Profile citations

  • OpenClaw / claim / operation-bound-grants

Source links

Primary links, including exact changelog lines when available.