{
  "version": "0.4.0",
  "settings": [
    {
      "group": "games",
      "key": "peer_play",
      "label": "Allow connected-player games",
      "default": true,
      "description": "Allow game invitations over signed WBchatterbox SYS messages. Each invitation requires acceptance. Busy declines new games.",
      "scope": "WB Four",
      "owner_only": true
    },
    {
      "group": "games",
      "key": "public_play",
      "label": "Allow public games",
      "default": false,
      "description": "Visitors can join games you explicitly open. A game capability grants no private Wotbox access.",
      "scope": "Public page and public WebMCP",
      "owner_only": true
    },
    {
      "group": "games",
      "key": "agent_play",
      "label": "Allow my agent to play games",
      "default": true,
      "description": "A scoped agent may play the opposing B side when you choose an agent opponent.",
      "scope": "Private WB Four agent tools",
      "owner_only": true
    },
    {
      "group": "games",
      "key": "agent_afk",
      "label": "Let my agent play for me while AFK",
      "default": false,
      "description": "When AFK is on, a connected authorized agent may take your turns against a human or public player. Wotbox queues events; it cannot wake a disconnected agent.",
      "scope": "Existing WB Four games",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "enabled",
      "label": "Enable agent social account",
      "default": true,
      "description": "Authorized agents share one visibly affiliated social identity. Individual tool grants are still required.",
      "scope": "Local agent social actions",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "private_posts",
      "label": "Let agents publish private posts",
      "default": true,
      "description": "Agents may publish to permitted private and group walls without a per-post confirmation.",
      "scope": "Private agent posts",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "public_posts",
      "label": "Let agents propose public posts",
      "default": true,
      "description": "Public agent posts wait for owner approval of the exact content and destinations.",
      "scope": "Public agent posts",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "act_for_owner",
      "label": "Let agents propose posts for me",
      "default": false,
      "description": "Separate permission to submit a human-attributed post. Each proposed post requires owner approval.",
      "scope": "Human social identity",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "invitations",
      "label": "Let agents propose People invitations",
      "default": false,
      "description": "An agent also needs the invitation tool grant; invitation acceptance stays in People.",
      "scope": "Agent social invitations",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "read_private",
      "label": "Let agents read private social posts",
      "default": true,
      "description": "Private access still needs the relevant read tool grant and destination scope.",
      "scope": "Agent private social reads",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "group_access",
      "label": "Let agents use group walls",
      "default": true,
      "description": "Group membership and the remote host permissions remain authoritative.",
      "scope": "Agent group reads and contributions",
      "owner_only": true
    },
    {
      "group": "social_agents",
      "key": "interactions",
      "label": "Let agents comment and like as agents",
      "default": true,
      "description": "Agent comments and likes retain the shared agent attribution and obey wall permissions.",
      "scope": "Agent social interactions",
      "owner_only": true
    },
    {
      "group": "files",
      "key": "expanded",
      "label": "Browse outside Wotbox",
      "default": false,
      "description": "Show paths outside the three instance locations after owner confirmation. OS permissions still apply.",
      "scope": "Owner file browser",
      "owner_only": true,
      "warning": "The file browser should not go outside of its scope. do you want to proceed Y/N?"
    },
    {
      "group": "files",
      "key": "edit_text",
      "label": "Edit standard text",
      "default": false,
      "description": "Allow saving .md and .txt files. No danger prompt for ordinary text.",
      "scope": "ReaderBox, including agent saves",
      "owner_only": true
    },
    {
      "group": "files",
      "key": "edit_protected",
      "label": "Edit configuration and source",
      "default": false,
      "description": "Allow protected text saves after confirmation of the exact changed content.",
      "scope": "ReaderBox, including agent saves",
      "owner_only": true,
      "warning": "Warning! changing this file may cause your system to fail. Are you sure your want to proceed? Y/N"
    },
    {
      "group": "files",
      "key": "confirm_trash",
      "label": "Confirm move to trash",
      "default": true,
      "description": "Require confirmation before moving a file or folder to trash. Permanent deletion always requires its own confirmation.",
      "scope": "FileBox human and agent operations",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "read",
      "label": "Read ordinary files",
      "default": true,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "create",
      "label": "Create folders and copy files",
      "default": true,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "organize",
      "label": "Rename and move ordinary files",
      "default": true,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "trash",
      "label": "Move ordinary files to trash",
      "default": true,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "edit_text",
      "label": "Edit standard text when ReaderBox editing is enabled",
      "default": true,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "edit_protected",
      "label": "Change protected configuration and source",
      "default": false,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "permanent_delete",
      "label": "Permanently delete from trash",
      "default": false,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "agents",
      "key": "expanded",
      "label": "Access expanded filesystem scope",
      "default": false,
      "description": "An operation also needs its individual agent grant and applicable app setting. Agents cannot change these settings or approve their own confirmation.",
      "scope": "Private file tools; does not constrain separate administrator SSH access",
      "owner_only": true
    },
    {
      "group": "transfer",
      "key": "max_file_bytes",
      "label": "Incoming file size",
      "default": 8388608,
      "description": "A valid advisory may exceed download limits. Retrieval requires approval, applicable limits and free space.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "bytes",
      "min": 1,
      "max": 1099511627776
    },
    {
      "group": "transfer",
      "key": "max_box_bytes",
      "label": "Incoming box size",
      "default": 67108864,
      "description": "A valid advisory may exceed download limits. Retrieval requires approval, applicable limits and free space.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "bytes",
      "min": 1,
      "max": 1099511627776
    },
    {
      "group": "transfer",
      "key": "max_box_files",
      "label": "Files per box",
      "default": 50,
      "description": "A valid advisory may exceed download limits. Retrieval requires approval, applicable limits and free space.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "files",
      "min": 1,
      "max": 200
    },
    {
      "group": "transfer",
      "key": "storage_bytes",
      "label": "Transfer storage allowance",
      "default": 268435456,
      "description": "A valid advisory may exceed download limits. Retrieval requires approval, applicable limits and free space.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "bytes",
      "min": 1,
      "max": 1099511627776
    },
    {
      "group": "transfer",
      "key": "social_attachment_bytes",
      "label": "WBsocial attachment size",
      "default": 8388608,
      "description": "Limits stored social media; does not permit new media types or wall access.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "bytes",
      "min": 1,
      "max": 33554432
    },
    {
      "group": "transfer",
      "key": "social_post_bytes",
      "label": "WBsocial attachments per post",
      "default": 16777216,
      "description": "Limits stored social media; does not permit new media types or wall access.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "bytes",
      "min": 1,
      "max": 33554432
    },
    {
      "group": "transfer",
      "key": "social_storage_bytes",
      "label": "WBsocial storage allowance",
      "default": 268435456,
      "description": "Limits stored social media; does not permit new media types or wall access.",
      "scope": "This node only; cannot override a remote owner",
      "owner_only": true,
      "unit": "bytes",
      "min": 1,
      "max": 1099511627776
    },
    {
      "group": "security",
      "key": "auto_block",
      "label": "Automatic temporary IP blocks",
      "default": true,
      "description": "Temporarily block repeated distinct denied public actions. An IP is not a verified person.",
      "scope": "Public entrance",
      "owner_only": true
    },
    {
      "group": "security",
      "key": "denial_threshold",
      "label": "Denied actions before a block",
      "default": 30,
      "description": "Distinct denied operations in a ten-minute window; ordinary identical retries are deduplicated.",
      "scope": "Public entrance",
      "owner_only": true,
      "min": 5,
      "max": 1000
    },
    {
      "group": "security",
      "key": "block_hours",
      "label": "Temporary block duration",
      "default": 24,
      "description": "Owner may review and remove blocks. Permanent blocks require an owner action.",
      "scope": "Public entrance",
      "owner_only": true,
      "min": 1,
      "max": 168
    },
    {
      "group": "profile",
      "key": "display_name",
      "label": "Public name",
      "default": "Wotbox",
      "description": "The name published when profile visibility is public.",
      "scope": "Public profile; does not change node identity",
      "reference_only": true
    },
    {
      "group": "profile",
      "key": "description",
      "label": "Introduction",
      "default": "",
      "description": "Owner-written introduction returned to visitors and public agents.",
      "scope": "Public profile when enabled",
      "reference_only": true
    },
    {
      "group": "profile",
      "key": "profile_visibility",
      "label": "Public profile",
      "default": "private",
      "description": "Private shows a generic Wotbox profile; public publishes name, introduction and selected interests.",
      "scope": "Public page and get_profile",
      "reference_only": true
    },
    {
      "group": "profile",
      "key": "topic_details",
      "label": "Interests and subtopics",
      "default": [],
      "description": "Select system topics and write personal subtopics. New categories can be suggested to the community.",
      "scope": "Profile visibility applies; also useful for private feed filtering",
      "reference_only": true
    },
    {
      "group": "appearance",
      "key": "afk",
      "label": "Away from keyboard",
      "default": false,
      "description": "The human signals they are away. Agent turns in existing peer/public games additionally require AFK delegation and a scoped live agent. This does not mean offline or Busy.",
      "scope": "Private desktop and game delegation",
      "reference_only": true
    },
    {
      "group": "appearance",
      "key": "theme",
      "label": "Theme",
      "default": "serenity",
      "description": "Select Serenity or Twilight.",
      "scope": "Private desktop default appearance",
      "reference_only": true
    },
    {
      "group": "appearance",
      "key": "presence",
      "label": "Presence",
      "default": "online",
      "description": "Busy tells visitors you are unavailable and suppresses routine communication notifications. Offline is detected, not selected.",
      "scope": "Public presence and private notifications",
      "reference_only": true
    },
    {
      "group": "views",
      "key": "selected",
      "label": "Selected view per app",
      "default": "default",
      "description": "One selected appearance configuration per app. Required controls and core permissions remain enforced.",
      "scope": "Layer 3 of the selected app",
      "reference_only": true
    },
    {
      "group": "sessions",
      "key": "multisession_warnings_enabled",
      "label": "Multisession warnings",
      "default": true,
      "description": "Notify when another session signs in.",
      "scope": "Owner sign-in sessions",
      "reference_only": true
    },
    {
      "group": "sessions",
      "key": "new_session_approval_required",
      "label": "Approve additional sessions",
      "default": false,
      "description": "Hold an additional authenticated session for approval while another is active.",
      "scope": "Owner browser access",
      "reference_only": true
    },
    {
      "group": "sessions",
      "key": "new_client_approval_required",
      "label": "Approve new browsers",
      "default": false,
      "description": "Hold an unfamiliar browser for approval while another session is active.",
      "scope": "Owner browser access",
      "reference_only": true
    },
    {
      "group": "agent_grants",
      "key": "scopes",
      "label": "Allowed agent operations",
      "default": "Selected read operations",
      "description": "A browser or paired agent can invoke only its granted tools. App settings further restrict the operation.",
      "scope": "One agent or the browser-agent policy",
      "reference_only": true
    },
    {
      "group": "agent_grants",
      "key": "destinations",
      "label": "Allowed destinations",
      "default": [],
      "description": "A nonempty list limits scoped outbound actions to the listed nodes or contacts.",
      "scope": "One paired-agent grant",
      "reference_only": true
    },
    {
      "group": "agent_grants",
      "key": "expires_at",
      "label": "Agent grant lifetime",
      "default": "Owner selected",
      "description": "Leases cannot exceed the grant expiry; revocation invalidates use.",
      "scope": "One paired agent; not independent SSH",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "permissions",
      "label": "Relationship permission matrix",
      "default": "Beta matrix",
      "description": "Acquaintance, friend, family and close family have independent checkboxes. Per-person overrides and space permissions also apply. No setting grants ownership.",
      "scope": "Incoming actions from accepted connections",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "chatterbox",
      "label": "WBchatterbox",
      "default": {
        "acquaintance": true,
        "friend": true,
        "family": true,
        "close-family": true
      },
      "description": "Send instant messages; the first-message gate may still require approval.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "postbox",
      "label": "WBpostbox",
      "default": {
        "acquaintance": true,
        "friend": true,
        "family": true,
        "close-family": true
      },
      "description": "Offer and retrieve accepted-contact mail. Automatic retrieval is a separate per-contact setting.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "files",
      "label": "File exchange",
      "default": {
        "acquaintance": true,
        "friend": true,
        "family": true,
        "close-family": true
      },
      "description": "Offer or retrieve files subject to explicit approval, storage and download limits.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "private_posts",
      "label": "Private-wall contributions",
      "default": {
        "acquaintance": false,
        "friend": false,
        "family": false,
        "close-family": false
      },
      "description": "Contribute a post without obtaining read access to the entire private wall.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "group_read",
      "label": "Read group walls",
      "default": {
        "acquaintance": true,
        "friend": true,
        "family": true,
        "close-family": true
      },
      "description": "Read a group wall only with explicit group membership.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "group_comment",
      "label": "Comment in groups",
      "default": {
        "acquaintance": false,
        "friend": true,
        "family": true,
        "close-family": true
      },
      "description": "Comment only where group membership also permits it.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "relationships",
      "key": "group_post",
      "label": "Post to groups",
      "default": {
        "acquaintance": false,
        "friend": false,
        "family": true,
        "close-family": true
      },
      "description": "Contribute only where group membership also permits it.",
      "scope": "Incoming authenticated peer actions; per-person settings may override defaults",
      "reference_only": true
    },
    {
      "group": "contacts",
      "key": "im_gate",
      "label": "First-message permission",
      "default": "pending",
      "description": "Acquaintances can have their first chatterbox message held for explicit approval.",
      "scope": "One accepted contact",
      "reference_only": true
    },
    {
      "group": "contacts",
      "key": "mail_auto_download",
      "label": "Automatic text mail",
      "default": false,
      "description": "Retrieve text-only WBpostbox automatically for this accepted contact. Files still require download approval.",
      "scope": "One accepted contact",
      "reference_only": true
    },
    {
      "group": "contacts",
      "key": "social_private_post",
      "label": "Private-wall posting",
      "default": false,
      "description": "Explicit permission to contribute a post to your private wall; does not reveal the whole wall.",
      "scope": "One accepted contact",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "display_name",
      "label": "WBsocial name",
      "default": "Wotbox owner",
      "description": "Name attached to social contributions.",
      "scope": "WBsocial attribution",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "address_visibility",
      "label": "Interaction address visibility",
      "default": "author",
      "description": "The post author sees your address after a like/comment; everyone sees it only when selected.",
      "scope": "WBsocial likes and comments",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "allow_repost",
      "label": "Allow reposting",
      "default": false,
      "description": "Allow attributed reposts of this post.",
      "scope": "One post",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "advertisement",
      "label": "Advertisement",
      "default": false,
      "description": "Identify promotional content as advertising.",
      "scope": "One post",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "ad_feedback",
      "label": "Ask why they liked it",
      "default": false,
      "description": "Offer brand, entertainment, knowledge and product reasons for likes on an advertisement.",
      "scope": "One advertisement",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "feed_mode",
      "label": "Feed interest mode",
      "default": "all",
      "description": "Show all posts, matching topics only, or matching topics first.",
      "scope": "Current wall selection",
      "reference_only": true
    },
    {
      "group": "groups",
      "key": "permission",
      "label": "Group member permission",
      "default": "No membership",
      "description": "Explicit group membership grants read, comment or contribute access, subject to owner relationship restrictions.",
      "scope": "One person in one group",
      "reference_only": true
    },
    {
      "group": "groups",
      "key": "family",
      "label": "Family group",
      "default": false,
      "description": "Restrict family-group content and videos to eligible family connections.",
      "scope": "One group wall",
      "reference_only": true
    },
    {
      "group": "social",
      "key": "keep_asset",
      "label": "Keep video",
      "default": false,
      "description": "Retain an accessible video on this droplet; otherwise it expires after seven days and spends two days in trash.",
      "scope": "One stored video",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "url",
      "label": "Public node URL",
      "default": "Chosen at installation",
      "description": "Canonical HTTPS address supplied by the installer owner; changing an established identity requires migration.",
      "scope": "This installation",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "dashboardPath",
      "label": "Private dashboard alias",
      "default": null,
      "description": "Optional separate private dashboard path; authentication is still required.",
      "scope": "This installation and its nginx route",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "port",
      "label": "Local service port",
      "default": "Installer selected",
      "description": "Loopback service port proxied by nginx.",
      "scope": "This installation",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "dataDir",
      "label": "Private data directory",
      "default": "Instance-specific",
      "description": "Stores this node’s private identity, messages, files and settings; never copied into packages.",
      "scope": "This installation",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "recoveryUser",
      "label": "Host recovery account",
      "default": null,
      "description": "Optional authorized OS account used for explicit host-password recovery.",
      "scope": "Host administration",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "socialHubUrl",
      "label": "Public social hub",
      "default": "https://wotbox.fun/",
      "description": "Shared WBsocial public-feed address. It is not the owner’s private feed.",
      "scope": "Public social federation",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "socialHub",
      "label": "Host a public hub",
      "default": false,
      "description": "Enable hub services; regular friend installations are not hubs.",
      "scope": "Host administration",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "communityEnabled",
      "label": "Community host",
      "default": false,
      "description": "Enable community/forum hosting; off for regular installations.",
      "scope": "Host administration",
      "reference_only": true
    },
    {
      "group": "host",
      "key": "entranceEdgeLog",
      "label": "Entrance edge log",
      "default": "Instance-specific",
      "description": "Read rejected nginx requests into WBlogbox. Successful routine presence checks are excluded.",
      "scope": "Private security reporting",
      "reference_only": true
    },
    {
      "group": "logging",
      "key": "retention",
      "label": "Entrance retention",
      "default": "30 days known / 90 days other",
      "description": "Known means locally recorded verified identity or owner. Counts do not prove malicious intent. Bounded at 50,000 events.",
      "scope": "Private WBlogbox storage",
      "reference_only": true
    },
    {
      "group": "files",
      "key": "associations",
      "label": "File associations",
      "default": "ReaderBox text handlers",
      "description": "Installed apps declare supported types and operations. Registrations never grant file access or execute command strings.",
      "scope": "FileBox dispatch",
      "reference_only": true
    }
  ]
}
