{"found":true,"collection":"patterns","library_url":"https://www.grokbotdb.com/library/pat.start-read-only","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"pat.start-read-only","name":"Start every integration read-only","category":"safety","problem":"Write access granted at connection time is never revisited.","technique":"Start read-only wherever the source system allows it, and record the fact of the scoping in shared knowledge so no Bot tries to route around a permission it thinks is a bug.","why_it_works":"Read-only removes the entire irreversible class of failure while you are still learning the workflow.","when_to_use":"Every new integration.","manual_ref":"5.3","evidence":"reported","related":["pat.scoped-service-accounts","pat.user-layer-routing-facts"],"confidence":"high","first_seen":"2026-09-03","last_verified":"2026-09-03"}}