Menu
All public files

config · v1.0.0 · Foo Guard

Read-only FAQ assistant

A synthetic configuration illustrating scoped tools, human approval and environment-based credentials.

Download

Import instructions preserve the exact version. Installing, saving to your private Library, and enabling Gateway are separate actions.

Requested access

Declared FAQ lookup and human handoff tools. This is a Foo Guard analysis template, not a native Claude or MCP client configuration.

Source · faq-assistant.json

{
  "id": "demo-faq-assistant",
  "name": "Secure FAQ Assistant",
  "description": "Synthetic production chatbot with scoped read-only access, env-based credentials, and human approval.",
  "owner": "platform-security",
  "sponsor": "customer-experience",
  "lifecycleState": "production",
  "model": "claude-sonnet-demo",
  "systemPrompt": "Answer only from approved FAQ articles. Escalate billing disputes to a human.",
  "tools": [
    {
      "name": "faq_lookup",
      "description": "Search indexed FAQ articles and return matching snippets",
      "readsData": true,
      "writesData": false,
      "executesShell": false,
      "accessesFilesystem": false,
      "accessesDatabase": false,
      "arbitraryHttp": false,
      "modifiesResources": false,
      "requiresApproval": false
    },
    {
      "name": "escalate_to_human",
      "description": "Return a handoff message when the user requests live support",
      "readsData": false,
      "writesData": false,
      "executesShell": false,
      "accessesFilesystem": false,
      "accessesDatabase": false,
      "arbitraryHttp": false,
      "modifiesResources": false
    }
  ],
  "permissions": [
    {
      "name": "faq.read",
      "scope": "faq:read",
      "resourceScope": "knowledge-base/faq",
      "accessLevel": "read",
      "wildcard": false,
      "administrative": false,
      "production": true,
      "granted": true
    }
  ],
  "credentials": [
    {
      "kind": "env-var",
      "name": "DEMO_LLM_API_KEY",
      "location": "env",
      "embedded": false,
      "shared": false,
      "longLived": false
    }
  ],
  "autonomy": {
    "maxIterations": 8,
    "humanApprovalRequired": true,
    "unlimited": false,
    "canModifyOwnConfiguration": false,
    "destructiveOperationsRequireApproval": true
  },
  "auditability": {
    "loggingEnabled": true,
    "tracingEnabled": true,
    "actionAttribution": true,
    "retentionDays": 180
  }
}

SHA-256: 553b12700b5149da47f6d96143613737ea5fe6b6449cbf6ac092c0df1c3be9e4

Deterministic scan evidence · Grade A

0 findings from a static scan of this exact source. No instructions were executed. Linked files, real tool permissions and runtime behavior are not verified.

Scan generated: 2026-10-11T00:19:51.972Z. Rules can change; rescan your copy after adapting it.

Report a concern through Support.

Reuse and attribution

This file is provided under the MIT license. Keep the accompanying copyright and permission notice when redistributing. Files are supplied without warranty.

View license