Access Map
Private
Auto‑updated
Marvin Access Map
Clear view of what Marvin can touch, what requires approval, and what’s protected.
Direct Access (no extra approval)
**Local system:** files under `/mnt/obsidian-vault/` and `/root/projects/`
**OpenClaw config/logs:** `/root/.openclaw/`
**CLI tools:** git, docker, ssh, curl, ping, dig, nc, etc.
**Obsidian vault:** read/write in permitted areas (projects, sessions, daily notes, marvin workspace); read-only in `telos/`
**Messaging:** Telegram to Michael
**Network checks:** ping/DNS/HTTP tests, LAN ICMP sweeps
**Browser automation:** available when browser relay is attached/available
Access with Credentials/Approval
Router/modem UI
Web dashboards (Vercel, Cloudflare, etc.)
Any service requiring logins not already configured
Protected Systems (always ask first)
**Proxmox .5** (dgtl-proxmox)
**TrueNAS .6/.9**
**AdGuard .20**
**MDM-SERVER**
Destructive git operations (force-push, reset --hard, delete main)
Notes
Do not stop/destroy CT 110 (self)
Never write secrets to the vault