Governed AI operations your leadership can trust
Fleet visibility, multi-agent Gateway architecture (up to 20+ agents per machine), WASM skill sandboxing where enabled, safety guardrails with human-in-the-loop, and controlled rollouts—so autonomous agents stay operational, secure, and within budget after pilots become production.
One place to see health, act fast, and keep agents running.
Fleet operations
- Fleet-wide visibility into health, incidents, costs, and early warning signals before the next failure.
- Predictive forecasting on CPU, RAM, and disk from metrics history so capacity issues surface before agents fail.
- Operator actions when things break: restart, rollback, restore from backup, and escalate with context.
- Configurable escalation policies and on-call rotation so the right owner is paged with full incident context.
- Secure connectivity so ops can reach every agent without agents reaching each other.
- Optional dedicated private mesh per customer so your agents never share a network with other tenants.
- Nightly drift scoring with behavioral, semantic, and environment dimensions—history charts and fleet heatmaps before customers feel degradation.
- Swarm drift detection flags correlated degradation across agents on a host or customer cohort—not just isolated outliers.
Technical details for security teams
- Command Center: fleet dashboard, per-machine and per-agent actions, Incidents (escalation, ClawGuard, resilience), releases, skills, billing, and immutable audit log.
- Tailscale hub-and-spoke ACLs; one Gateway on :8000 routes multiple agent runtimes per machine; dedicated customer mesh available for sovereign isolation.
- Scheduled per-agent backups with offsite copy; restore to last known good or rollback code; aggregated health per machine.
- Composite drift scores, 7–30 day history charts, continuity snapshot timeline with manual realign, and a fleet Agent Quality heatmap.
- Nightly fleet operations: drift scoring, known-good snapshot capture, graduated auto-realign (L1–L5) with approval gates; trajectory spans with trace IDs and cost attribution.
Up to 20+ agents and 10 claw types behind one Gateway per machine—the structural edge single-bot vendors cannot match.
Multi-agent fleet architecture
- Run heterogeneous agents (OpenClaw, NanoClaw, and eight other claw types) on one host without fragile monolith sprawl.
- WASM-isolated custom skills with capability tokens so executable logic never runs directly on the host filesystem.
- Cross-agent prompt context cache on the Gateway cuts duplicate tokens and latency when agents share long system prompts.
- Staging resilience drills produce a client-facing scorecard—proof your guardrails detect injection and alert paths before production waves.
Technical details for security teams
- Gateway aggregates health, backups, ClawGuard middleware, and context-cache metrics to Command Center heartbeats.
- OpenClaw WASM tier: wasmtime sandbox, manifest + capability tokens, catalog install gates for zip hardening.
- Gateway context cache (observe + optimize modes); Command Center reports cache savings per machine.
- Resilience scorecard in the client portal; operator resilience validation history from staging drills.
What your customers and procurement teams actually see.
Client portal
- Branded portal per customer with live machine status, SLA tracking, and uptime they can trust.
- Support tickets with priority tracking and satisfaction feedback after resolution—no shadow email threads.
- Client-visible help articles and runbooks so your buyers self-serve without opening ops tickets.
- Agent Quality scorecard: drift status (in policy / watch / breach), sanitized flagged conversations, and continuity attestations buyers can audit.
- Monthly Proof of Operations PDF archive—uptime, drift averages, safety blocks, and token spend in one leadership-ready report.
- Proof of Compliance certificate, identity verification, resilience scorecard, and SLA breach credit visibility.
- Partner MSP view: multi-tenant portal for partners managing many customer fleets from one branded surface.
Technical details for security teams
- White-label branding per customer; Agent Quality drift scorecard; monthly Proof of Operations PDF archive.
- SLA tracker wired to managed continuity; Stripe invoices and plan management in-portal; SLA breach credits ledger for transparent remediation.
Guardrails and evidence security and audit teams expect.
Safety & governance
- Central safety policies applied consistently across machines and agents.
- Violations surfaced with evidence your security team can review, not buried in logs.
- Human-in-the-loop approval for high-risk tool actions and high-risk drift realignments before execution proceeds.
- Immutable audit trails, continuity attestations, and optional Concordium anchoring—including CIS-8004 agent registry—for SOC 2 and procurement.
Technical details for security teams
- ClawGuard: policy management, per-machine and per-agent assignments, agent-level tool validation and prompt sanitisation, gateway request/response inspection, violation feed.
- Safety pending-actions queue with operator approve/deny; workflow-routed approval routing for high-risk actions.
- CIS-8004 on-chain agent register/verify/revoke; public Agent Card JSON; continuity attestations hash-anchored on Concordium where configured.
- Operator audit log with full action history; client portal SLA, tickets, Agent Quality, and compliance reporting.
Control spend and stay free of single-vendor lock-in.
Cost & providers
- Per-customer token budgets with hard caps, pre-request gates, and alerts so autonomous workloads stay profitable.
- Use OpenAI, Anthropic, Google, AWS, or on-prem models, switch without re-architecting the fleet.
- Gateway context cache reduces repeated prompt spend when multiple agents share the same machine.
- Managed keys or bring-your-own with rotation visibility finance and security can audit.
Technical details for security teams
- Providers: OpenAI, Anthropic, Google Vertex (Gemini), AWS Bedrock, Ollama for private cloud.
- Pre-request budget checks; usage reporting for managed and BYOK billing tiers in Command Center.
- Per-machine context-cache hit rate and bytes saved reported via Gateway heartbeat.
Upgrade agents and extend capability without surprise breakage.
Ship with confidence
- Roll out agent updates through phased validation with automatic rollback when something regresses.
- Per-customer auto-update policies with maintenance windows so production waves land when your teams expect them.
- Extend agents with vetted skills—including WASM sandbox tier—quarantine, test, and release before fleet-wide install.
- Blueprint evaluation pipeline scores agent configs against golden cases before publish.
- Structured agent blueprints define purpose, tools, memory, and continuity policy (auto-realign levels, approval gates) in versioned form.
Technical details for security teams
- Release pipeline: dev, then staging, then canary, then wave rollouts with regression gates; SOUL.md, skills, and memory configs versioned per claw type.
- Skill catalog with quarantine workflow and architect release gate; ClawHub sync; WASM execution tier in catalog metadata.
- Automated blueprint evaluation before publish; eval-pass snapshots become known-good restore points.
- Blueprint continuity config: auto-realign L1–L5 ladder, max level, and require-approval-above thresholds per agent.
Prove fit on your infrastructure before a managed retainer.
Evaluate & deploy
- Download installers for your OS and validate on your VPC or on-prem, no secrets on the marketing site.
- Day 0: copy-paste bootstrap from Command Center — online in minutes, not days.
- Client portal install hub issues personalized commands and tracks progress—credentials never appear on this marketing site.
- Flexible runtime per machine: systemd on bare metal, full Docker stack, or hybrid (recommended) without re-architecting the fleet.
- Optional sovereign node: dedicated mesh on your premises or customer-owned cloud so agents stay on your network boundary.
- Personalized onboarding and credentials issued only through Command Center when you are ready.
- Same platform operators use in live engagements, so evaluation matches production reality.
Technical details for security teams
- Debian, Ubuntu, Fedora, plus community portable Linux, macOS, and Windows packages from threesixty.co/claw-tools/latest.
- Operators and clients mint Tailscale keys and personalized install commands in the portal; install progress is tracked until the machine heartbeats.
See it in your environment
Book a live demo or start with a 48-hour AI Health Audit we will map your agent footprint to the platform capabilities you need first.
Book a live demo