Permissions describe contribution intent
A manifest can request capabilities such as reading project metadata, registering a command, or contributing a provider definition.
Permission approval is explicit
Install and update flows should show new or changed permissions instead of preserving approval silently.
Plan and access checks still apply
Extension permissions cannot bypass server-provided LobeWork access, organization policy, or other authorization checks.
Source trust matters
Official, third-party, and local sources remain visible. Verified publisher status does not remove the need to review permissions.
Current permissions do not enable arbitrary code
The LobeWork v1 release is manifest-only; permission labels do not create a hidden JavaScript, native, shell, or installer execution path.
Ask LobeWork about this guide.
Ask LobeWork uses the same published article library and links back to its source guidance.