Golden paths now explicitly call out that TCC privacy permissions cannot be fully declarative on unmanaged Macs.
- Add golden paths doc and link from README\n- Default workspaceDir to stateDir/workspace and pin agents.defaults.workspace when unset\n- Fix macOS app defaults domain and add openclaw.nixMode toggle