docs: distinguish Codex and Feishu write permissions
This commit is contained in:
@@ -85,4 +85,6 @@ This is a pilot package. It is not a formal company AM, official system, custome
|
||||
|
||||
AR51 owns AM516 rules, functional design, implementation, validation, iteration, network access, account permissions, API-key use, and outbound-transfer approval. TH8 is the supporting IT department but owns only Git repository and synchronization-mechanism construction in this project. Outbound API access remains disabled until AR51 creates a trusted approval record explicitly covering `api.zeroerr-agent.com`, the AM516 use case, and API-key use.
|
||||
|
||||
The Feishu bot is read/output/record-only: it may read approved project sources, return results, and append to the fixed delivery record file. It may not write back any rule, Skill, script, prompt, configuration, documentation, or other project content.
|
||||
Mac Studio Codex and the Feishu bot have different file permissions. When AR51 directly initiates or authorizes Codex through a non-Feishu local entry point, including a Codex automation or scheduled task, Codex may modify and write project files and perform Git operations within the assigned task scope.
|
||||
|
||||
The Feishu bot remains read/output/record-only: it may read approved project sources, return results, and append to the fixed delivery record file. It may not write back any rule, Skill, script, prompt, configuration, documentation, Git metadata, or other project content. A Feishu request does not inherit local Codex write permission even when Codex is the underlying executor.
|
||||
|
||||
Reference in New Issue
Block a user