REF: AIO-010
Permissions
PHO Architects permissions view for approved tools, files, devices, execution rules, human review, and client-visible data boundaries.
Local FallbackProfile
Approved tools
05
Integrations
Approved devices
01
Infrastructure
SSH allowed
No
Credential safe
Visible data
34
10 internal
Permission Summary
AIO-010| Permission | Setting | Scope |
|---|---|---|
| Approved tools | AIO Ops App, Obsidian, Google Workspace, Dropbox MCP, Miro MCP | Visible integrations only |
| Approved folders/files | Gmail/Drive/Calendar, PHO project folders | Folder/file scope without secrets |
| Approved devices | PHO MacBook | Client-visible infrastructure |
| SSH allowed | No | No raw keys or passwords stored |
| Agent execution allowed | Yes | Visible agent execution boundary |
| Human approval required | Yes | Pending sensitive action control |
| Client-visible data settings | 34 visible / 10 internal | Visible/internal record split |
Approved Tools
No Secrets| Provider | Name | Status | Permission | Summary |
|---|---|---|---|---|
| Hermes | AIO Hermes profile fleet | Connected | Internal only | Four AIO-only Hermes profiles on AIO Ops Mac: Orchestrator, Systems Monitor, Client Ops Analyst, and Remediation Builder. |
| OpenClaw | Prompt-only Hermes watcher | Planned | Internal only | Single OpenClaw watcher agent, used only when prompted, to check Hermes profile health. |
| AIO Ops App | PHO internal workspace | Connected | Approved | Control-plane route /internal/clients/pho-architects backed by local fallback data until Supabase live credentials are wired. |
| Obsidian | PHO Brain | Connected | Approved | Canonical vault: /Users/phoarchitects/Vaults/PhoArchitects-Brain |
| Slack | PHO Slack routing | Connected | Internal only | Default/gslack gateway owns Slack delivery; specialist PHO gateways run without SLACK_* tokens to avoid socket conflict. |
| Google Workspace | Gmail/Drive/Calendar | Connected | Approved | Used for scoped Gmail searches, draft creation, Drive meeting/project context; no automatic sends. |
| Dropbox MCP | PHO project folders | Connected | Approved | Approved Dropbox paths including /Pho Architects, Inc/26008_546_46th and _Proposal convention. |
| Miro MCP | PHO workflow/project boards | Connected | Approved | Miro boards available for workflow/SOP/project context; baseline boards are read/list first before writes. |
Approved Devices
Access Scope| Device | Type | Access | Permission | Purpose |
|---|---|---|---|---|
| AIO Ops Mac | Mac mini edge node | Tailscale SSH available | Internal only | Clean AIO edge-node host for PHO Hermes agents and prompt-only OpenClaw monitoring |
| PHO MacBook | MacBook | SSH available via pho-macbook | Approved | Runs PHO Hermes/OpenClaw profiles, PHO Brain, integrations, and local workflow automation. |
Client-Visible Data Settings
Visibility Split| Record Type | Client Visible | Internal Only |
|---|---|---|
| Workflows | 14 | 2 |
| Tickets | 1 | 1 |
| Agents | 6 | 3 |
| Tasks | 0 | 0 |
| Reports | 0 | 0 |
| Events | 2 | 0 |