> Canonical guide: https://developers.foxlight.ai/build/permissions/
> Contract snapshots: Skulk 2.0.0 (b0af39c79b6b7102b2478062904f1d7cc8619975); SDK 0.4.0 (31bb090b8f64689f87514e48385e22b6ad94a6c2). Check the installed runtime when versions differ.

# Permissions and approval

Capabilities and plugin management use explicit permission scopes. Discovery does not authorize an effect, and a descriptor’s revision does not authorize a caller.

## How it works

Bind approvals to the exact target, normalized plan, bounds, revision and idempotency identity. A plugin must enforce its own provider effects through the host-approved path. Keep secret material out of configuration schemas and diagnostic output.

## Complete contract

Read the [Skulk 2.0 development guide](https://docs.foxlight.ai/skulk/next/api-guide/#managed-plugin-lifecycle-and-setup) for the complete parameters, constraints, examples and operational behavior.
