Skip to content

Simplify: bot read-only on autoresearch, no separate deploy PAT - #7

Merged
renmengye merged 1 commit into
mainfrom
docs/bot-read-access
Aug 5, 2026
Merged

renmengye merged 1 commit into
mainfrom
docs/bot-read-access

Conversation

@renmengye

Copy link
Copy Markdown
Member

Mengye's over-engineering challenge held up: read denial protected nothing (sessions share the filesystem with the deploy clone; the repo holds no secrets) and forced a third credential. Now: bot has a Read collaborator role here, the intersection rule makes its existing token read-only on this repo, deploy pulls use it, and write remains impossible at the account layer — which was always the real control.

🤖 Generated with Claude Code

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant