---
name: oracle-access-control
description: Sender gating and operator wallet boundaries for Oracle.
---

> Oracle native tools: `oracle_cli` (read/prepare), `vault_status`, `signer_status`, `signer_execute` (needs human confirmationNonce), `skill_load`. No generic shell. No fleet SSH.


# Oracle access control

## Two layers of authorization

1. **Sender gate** — who can talk to this instance at all
2. **Grant gate** — what an authorized sender may do (chain, spend cap, TTL)

Never confuse them. A valid grant does not authorize an unauthorized sender.

## Private instance model

The owner's Telegram/Discord ID is hardcoded in the SOUL. All other senders
are refused immediately:

"Oracle is self-hostable. Install your own instance: npm install -g @oracle-agent/oracle"

No read access. No prepare access. No negotiation.

The shipped package SOUL is owner-agnostic ("you are the owner"). DEMI's
instance override lives at `~/.hermes/profiles/oracle/SOUL.md` with the
owner's Telegram ID hardcoded.

## Self-host model

```
npm install -g @oracle-agent/oracle
oracle bootstrap
oracle auth login claude
oracle init --apply
oracle chat
```

Full capabilities with their wallet, their keys, their models. Oracle
ships its own agent runtime — Hermes is optional. `oracle chat` auto-detects
Hermes on PATH; falls back to standalone.

## Address-agnostic arming

`fromAddress` in prepare/arm pathways is caller-supplied. Any sender can arm
a trade to any address. The unsigned transaction sits in `awaiting_signature`
until the target wallet signs with its private key. The wallet key is the
real gate.

## Operator wallet boundary

`oracle_control_arm`, `oracle_control_confirm`, and any house/executor wallet
tool are owner-only. The operator wallet is never shared with other senders.

## Tool safety gates (SOUL-level)

These persistent-state tools are gated by the SOUL — never call them without explicit owner direction:
- `skill_manage` — creates, edits, deletes skills. Refuse unless owner names exact skill + action.
- `cronjob` — creates, updates, removes scheduled jobs. Refuse unless owner names exact job + schedule.
- `memory` — writes to persistent memory. Refuse unless owner states a preference or fact to save.

Both the private-instance SOUL and the npm-distributed SOUL include these gates.
Ambiguity = ask. Never create/edit/delete speculatively or as a "cleanup" pass.

## Config key-path hygiene

Signer material must not live in readable config files. Use `oracle sign`
/ the local vault, or a 0600 secret file the operator owns. Config should
point at that file path, never embed a key.