# Identity and roles

> Pairing, operator scopes, role ceilings, and the one-gateway-is-one-trust-domain boundary

- 网址：https://funcoding.ai/agents/openclaw/start/why-openclaw/identity-and-roles/
- 来源：OpenClaw 官方文档原文（英文），MIT 许可，同步于 2026-10-11
- 官方原文：https://docs.openclaw.ai/zh-CN/start/why-openclaw/identity-and-roles

---
Device-authenticated control-plane clients present signed identities and go through [pairing](https://funcoding.ai/agents/openclaw/gateway/pairing/). Reconnecting with broader device scopes requires approval. Other admission paths include verified front doors and configured local or shared-secret access. With DM policy set to [pairing](https://funcoding.ai/agents/openclaw/channels/pairing/), unknown senders get a pairing code, not the agent. Identity-aware front doors ([Tailscale](https://funcoding.ai/agents/openclaw/gateway/tailscale/), [trusted proxy](https://funcoding.ai/agents/openclaw/gateway/trusted-proxy-auth/), [Cloudflare Access](https://funcoding.ai/agents/openclaw/gateway/cloudflare-access/)) map verified identities to scopes.

Eight [operator scopes](https://funcoding.ai/agents/openclaw/gateway/operator-scopes/) — `read`, `write`, `admin`, plus narrower ones for pairing, approvals, questions, and talk — are derived per request from the actual parameters before dispatch, and methods with no scope classification are denied rather than allowed. Write and admin operations require their corresponding scopes. [`gateway.roles`](https://funcoding.ai/agents/openclaw/gateway/operator-scopes/) assigns named person-level roles: visibility into other people's sessions, an agent allow-list, and a scope ceiling that is intersected with whatever connection auth granted, never added to it. Profiles without a valid assignment receive the configured default role; configure that role as deny-all for a hardened deployment. Omitting `gateway.roles` leaves the role boundary disabled. [Multi-user sessions](https://funcoding.ai/agents/openclaw/concepts/multi-user/) record an immutable creator, an assignable owner, and a bounded participant history, and verified GitHub identity can flow through to `Co-authored-by` trailers and PR-linked session transcripts ([user model](https://funcoding.ai/agents/openclaw/concepts/user-model/)).

Our [security docs](https://funcoding.ai/agents/openclaw/gateway/security/) define the scope: one gateway is one trust domain. Roles organize collaboration between people who already trust each other. For mutually untrusted tenants, run separate gateways with their own state and credentials, ideally under separate OS users or hosts. See the [security trust model](https://funcoding.ai/agents/openclaw/gateway/security/trust-model/).
