Time since OpenClaw first launched: Almost a year (Source: OpenClaw Foundation blog (September 30, 2026))
Giving an AI agent access to company systems is a governance decision before it is a technical one. On September 30 the OpenClaw Foundation announced OpenClaw Enterprise (OCE), an open source platform for running persistent agents. These are agents that stay running and keep access to company systems. The Foundation says deployment of persistent agents remains limited because organizations want a stronger governance standard first. It adds that most IT departments simply block platforms like OpenClaw.
What was announced
OCE is vendor neutral and MIT licensed. OpenClaw says it started at OpenAI, was donated to the OpenClaw Foundation, and has since been developed with Red Hat and Nvidia. Red Hat and OpenAI are piloting it internally.
Companies can self-host it today. Docker Compose is supported for local development, and Kubernetes for internal deployment. VentureBeat notes that the software is free, but companies still pay for their own compute, models, storage and operations.
The stage matters. OpenClaw describes OCE as something organizations can use for internal pilot workloads, with 1.0 planned later this year.
How it works
OCE is a control plane. That is the layer that decides who may deploy an agent, what it may touch, and what gets recorded. It does not replace the agent itself.
OpenClaw lists several parts. Multi-tenancy lets separate teams share one platform without sharing access. Hard boundaries separate trusted from untrusted workloads. Sandboxing runs agents in isolated environments. Fine-grained permissions limit what each agent can do. Language models also review agent actions.
The core pieces can be swapped. The model, the harness (the software loop that lets a model use tools) and the sandbox can each come from a third party or from inside the company. VentureBeat reports that the project's repository calls OCE "Kubernetes for agents".
The idea: access is the product and the risk
The lesson here is that an agent's usefulness and its risk come from the same source: access. An agent that can fix a broken build must be able to read the code and change it. Security teams may focus on that second fact first. That could help explain the blocking OpenClaw describes.
VentureBeat frames this as a wider shift in the agent market. In its reading, the hard question is increasingly whether a company can safely let many agents touch production systems, not whether a model can do the task.
Consider the on-call engineer. OpenAI staff member RJ Marsan describes an internal agent, Androidclaw, that can find the pull request behind a broken build and fix it. He says it answered a report of a vanished work tab with a link to the incident in "like 30 seconds". Now consider the security lead who must approve that agent. OpenClaw says OpenAI's own agents already have complete reach into its code and plugins.
That figure is one anecdote from one person. It is not a fix time.
The comparison with Kubernetes is fair. It did not make containers smarter. It made them possible to manage at scale. OCE is a bet that agents need the same kind of layer before most organizations will run them.
What is not yet known
This is OpenClaw's own account of its own product. The sources report no independent testing of the security controls.
OpenClaw says a reference architecture showing how the protections work together will come in the coming weeks. Until then, buyers lack the project's own account of how the protections fit together.
The review step also raises a question. One language model checks the actions of another. The sources do not say how well that works.
Questions to put to your team
Which agents already run in our environment, and what can each one reach? A ban only works if it is enforced.
If we pilot, what is the smallest scope that teaches us something? OpenClaw describes OCE as usable for internal pilots today.
Can we reconstruct what an agent did, and who approved its access? Ask to see the audit records, not a description of them.
Which parts do we own? The model, harness and sandbox can be swapped, so decide who is accountable for each.
Intelligence gets an agent noticed. Permissions decide whether it is allowed to stay.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: OpenClaw.





