Reads and edits are not confined to the workspace: any path on this machine works here too. Two places are off-limits to edits — the registered project workspaces, where the work belongs to that project's manager, and the product's own live databases and the copies it keeps of them, under its data directory. The live databases are off-limits to reads as well: no tool opens one, because opening a live database from inside the running service silently releases the locks it holds on it, and the `mahbot_debug` tool is how the product's own data is read.