Read-only FAQ assistant
A synthetic configuration illustrating scoped tools, human approval and environment-based credentials.
Requested access
Declared FAQ lookup and human handoff tools. This is a Foo Guard analysis template, not a native Claude or MCP client configuration.
Source · faq-assistant.json
{
"id": "demo-faq-assistant",
"name": "Secure FAQ Assistant",
"description": "Synthetic production chatbot with scoped read-only access, env-based credentials, and human approval.",
"owner": "platform-security",
"sponsor": "customer-experience",
"lifecycleState": "production",
"model": "claude-sonnet-demo",
"systemPrompt": "Answer only from approved FAQ articles. Escalate billing disputes to a human.",
"tools": [
{
"name": "faq_lookup",
"description": "Search indexed FAQ articles and return matching snippets",
"readsData": true,
"writesData": false,
"executesShell": false,
"accessesFilesystem": false,
"accessesDatabase": false,
"arbitraryHttp": false,
"modifiesResources": false,
"requiresApproval": false
},
{
"name": "escalate_to_human",
"description": "Return a handoff message when the user requests live support",
"readsData": false,
"writesData": false,
"executesShell": false,
"accessesFilesystem": false,
"accessesDatabase": false,
"arbitraryHttp": false,
"modifiesResources": false
}
],
"permissions": [
{
"name": "faq.read",
"scope": "faq:read",
"resourceScope": "knowledge-base/faq",
"accessLevel": "read",
"wildcard": false,
"administrative": false,
"production": true,
"granted": true
}
],
"credentials": [
{
"kind": "env-var",
"name": "DEMO_LLM_API_KEY",
"location": "env",
"embedded": false,
"shared": false,
"longLived": false
}
],
"autonomy": {
"maxIterations": 8,
"humanApprovalRequired": true,
"unlimited": false,
"canModifyOwnConfiguration": false,
"destructiveOperationsRequireApproval": true
},
"auditability": {
"loggingEnabled": true,
"tracingEnabled": true,
"actionAttribution": true,
"retentionDays": 180
}
}
Deterministic scan evidence · Grade A
0 findings from a static scan of this exact source. No instructions were executed. Linked files, real tool permissions and runtime behavior are not verified.
Reuse and attribution
This file is provided under the MIT license. Keep the accompanying copyright and permission notice when redistributing. Files are supplied without warranty.
View license