{"found":true,"collection":"patterns","library_url":"https://www.grokbotdb.com/library/pat.scoped-permissions-over-written-boundaries","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"pat.scoped-permissions-over-written-boundaries","name":"Scope the credential rather than instructing restraint","category":"safety","problem":"The most serious circulating incident is a Bot with infrastructure permissions that created resources in the wrong region and, in resolving the mess, deleted a live production site.","technique":"A Bot with credentials that can destroy something should have those credentials scoped so it cannot, rather than instructions telling it not to.","why_it_works":"Written boundaries are a control on intent; scoped permissions are a control on outcome. There is no dry run, and approvals gate the proposed action rather than the cleanup the Bot improvises afterwards.","when_to_use":"Any Bot touching infrastructure, production or deletion.","manual_ref":"5.6","evidence":"reported","source_url":"https://grokbotguide.com/pain-points","related":["pat.scoped-service-accounts","pat.approvals-do-not-reverse","pat.beta-do-not-connect-list"],"confidence":"high","first_seen":"2026-09-03","last_verified":"2026-09-03"}}