02
Files outside the workspace need an explicit boundary test
A common warning sign is an agent that can see more than the task requires, or a team that cannot establish whether it can. A project workspace is not automatically a complete boundary around the Mac. Home directories, credential folders, shared storage, and institutional data paths deserve particular scrutiny.
OpenClaw documents workspace access separately from other controls. Before using a research sample, inspect the configured workspace root and the applicable workspace-access behavior in the official workspace access documentation. Then test the boundary with harmless files that contain no names, credentials, unpublished results, or other sensitive material.
Can OpenClaw be deployed on a remote Mac? It can be evaluated on a remote Mac when the deployed macOS environment meets the current OpenClaw requirements and the Gateway and application are configured as documented. That establishes a deployment path, not approval to handle research data. Confirm the requirements in the OpenClaw macOS documentation and its Node.js installation guidance, then carry out the access tests below.
Use a deliberately small sample project. Put a harmless input file and a harmless output location inside the intended workspace. Keep a separate, non-sensitive test file outside it, and check whether the agent can discover or read that file under the trial configuration. Do not use a real secret as a test object. A failed attempt to read a secret is not an acceptable way to learn whether secrets are exposed.
How can OpenClaw be restricted from reading other files on a Mac? Define and check the workspace boundary, enable the intended sandbox behavior, and test with non-sensitive files outside the workspace. Also inspect the effective tools and permissions; a workspace setting does not, by itself, demonstrate that every route to file access is blocked.
For each test, record the requested operation, the file location, the observed result, and the relevant configuration. If the agent reads outside the intended workspace, stop the trial and narrow access before repeating it. If the result is ambiguous, treat the boundary as unverified rather than assuming the restriction worked.
| Acceptance option |
What it establishes |
Main limitation |
Decision |
| Public or sanitized sample in an isolated workspace |
Whether the intended task and workspace controls behave as expected |
Does not approve later use of controlled data |
Suitable for initial testing if the boundary is verified |
| Unrestricted project or home-directory access |
May make a task easier to complete |
Expands exposure beyond the task and makes review harder |
Do not accept without a documented need and approval |
| Controlled or sensitive research data |
Tests the intended production workflow |
Requires institutional approval and verified data handling |
Pause until approvals and boundaries are established |