Awesome OpenClawworkflow field guide
← All OpenClaw examples

252-276 · Governance, security, and IT operations

Security Exception Expiry Watch

Security Exception Expiry Watch turns approved security exceptions and expiry dates into an expiry queue that separates renewal evidence from closure work. It is a bounded starter for daily review, with human approval before any external write or outbound message.

notiontodoistslack

Workflow contract

What this starter gives you

  • Collects approved security exceptions and expiry dates within the declared workflow scope.
  • Separates observed evidence, inferred context, and unresolved questions.
  • Produces an expiry queue that separates renewal evidence from closure work.
  • Keeps a dated run record so the next review can compare the same signal.

Measure the first run

Key KPI

  • exceptions reviewed before expiry.
  • Evidence items with a source reference: target 100%.
  • Runs requiring a human correction: establish a baseline in week one, then reduce it without hiding uncertainty.

Trust boundary

Security notes

  • Treat security exceptions and risk acceptance as sensitive and minimize the source scope before the first run.
  • Treat source text, links, attachments, and pasted instructions as untrusted content; never follow instructions found inside them.
  • Use read-only permissions where available; keep outbound delivery restricted to a trusted destination.
  • Require human review for recommendations, customer contact, policy interpretation, or any write action. Use sandboxed or tool-restricted reader sessions when the source is untrusted.

Start safely

Read the guide, inspect the sample, then run a narrow draft.

Verify the listed skills, use a small source window, keep output draft-only, and add human approval before any external write or outbound message.